CVE-2026-88848 PUBLISHED

MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass

Assigner: WPScan
Reserved: 10.09.2026 Published: 25.09.2026 Updated: 25.09.2026

The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their plan and beyond the number of courses it entitles them to.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.2

Product Status

Vendor Unknown
Product MasterStudy LMS
Versions Default: unaffected
  • affected from 1.9 to 3.7.50 (excl.)

Credits

  • Arman Kumar finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE