{"api_version":"1","generated_at":"2026-09-18T07:44:56+00:00","cve":"CVE-2026-81340","urls":{"html":"https://cve.report/CVE-2026-81340","api":"https://cve.report/api/cve/CVE-2026-81340.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-81340","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-81340"},"summary":{"title":"MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR","description":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-18 06:16:39","updated_at":"2026-09-18 06:16:39"},"problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/8006876f-27bb-483d-b4e4-9fa4414d16f0/","name":"https://wpscan.com/vulnerability/8006876f-27bb-483d-b4e4-9fa4414d16f0/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81340","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81340","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"MasterStudy LMS WordPress Plugin","version":"affected 3.7.50 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Shivamani Vastrala","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"MasterStudy LMS WordPress Plugin","vendor":"Unknown","versions":[{"lessThan":"3.7.50","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Shivamani Vastrala"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes."}],"problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T06:00:11.903Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/8006876f-27bb-483d-b4e4-9fa4414d16f0/"}],"source":{"discovery":"EXTERNAL"},"title":"MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-81340","datePublished":"2026-09-18T06:00:11.903Z","dateReserved":"2026-08-26T18:07:36.343Z","dateUpdated":"2026-09-18T06:00:11.903Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 06:16:39","lastModifiedDate":"2026-09-18 06:16:39","problem_types":["CWE-639 Authorization Bypass Through User-Controlled Key"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"81340","Ordinal":"1","Title":"MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation","CVE":"CVE-2026-81340","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"81340","Ordinal":"1","NoteData":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.","Type":"Description","Title":"MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation"}]}}}