PoC Index82,564 CVEs with PoCs

CVE-2026-81195

MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route

MEDIUM 5.3EPSS 0.2%

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.

Affected
MasterStudy LMS WordPress Plugin
CVSS v3.1 CNA
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.21% chance of exploitation in the next 30 days, 11th percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References