WordPress Plugin Vulnerabilities

MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN

Description

The plugin does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Abdullah Kareem
Submitter
Abdullah Kareem
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-27 (about 2 days ago)
Added
2026-08-27 (about 1 day ago)
Last Updated
2026-08-27 (about 1 day ago)

Other