WordPress Plugin Vulnerabilities
MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass
Description
The plugin does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their plan and beyond the number of courses it entitles them to.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Arman Kumar
Submitter
Arman Kumar
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-22 (about 3 days ago)
Added
2026-09-22 (about 2 days ago)
Last Updated
2026-09-22 (about 2 days ago)