{"api_version":"1","generated_at":"2026-08-29T12:12:57+00:00","cve":"CVE-2026-81200","urls":{"html":"https://cve.report/CVE-2026-81200","api":"https://cve.report/api/cve/CVE-2026-81200.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-81200","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-81200"},"summary":{"title":"MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR","description":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-29 06:17:58","updated_at":"2026-08-29 06:17:58"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/1a4db76f-7043-4f9e-a584-17151d008ab1/","name":"https://wpscan.com/vulnerability/1a4db76f-7043-4f9e-a584-17151d008ab1/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81200","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81200","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"MasterStudy LMS WordPress Plugin","version":"affected 3.7.42 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Revanth Hari Narayana Matte","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"MasterStudy LMS WordPress Plugin","vendor":"Unknown","versions":[{"lessThan":"3.7.42","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Revanth Hari Narayana Matte"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-29T06:00:23.771Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/1a4db76f-7043-4f9e-a584-17151d008ab1/"}],"source":{"discovery":"EXTERNAL"},"title":"MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-81200","datePublished":"2026-08-29T06:00:23.771Z","dateReserved":"2026-08-26T16:32:40.316Z","dateUpdated":"2026-08-29T06:00:23.771Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-29 06:17:58","lastModifiedDate":"2026-08-29 06:17:58","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"81200","Ordinal":"1","Title":"MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billin","CVE":"CVE-2026-81200","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"81200","Ordinal":"1","NoteData":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.","Type":"Description","Title":"MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billin"}]}}}