CVE-2026-81026 PUBLISHED

MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN

Assigner: WPScan
Reserved: 26.08.2026 Published: 29.08.2026 Updated: 29.08.2026

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.

Product Status

Vendor Unknown
Product MasterStudy LMS WordPress Plugin
Versions Default: unaffected
  • affected from 0 to 3.7.40 (excl.)

Credits

  • Abdullah Kareem finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE