PoC Index82,564 CVEs with PoCs

CVE-2026-81198

MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR

LOW 3.8EPSS 0.2%

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.

Affected
MasterStudy LMS WordPress Plugin
CVSS v3.1 CNA
3.8 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
EPSS
0.19% chance of exploitation in the next 30 days, 8th percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References