MasterStudy LMS WordPress 插件在 3.7.50 版本之前存在一个安全漏洞:该插件在返回课程的已注册学生数据之前,未验证请求用户是否为该课程的拥有者。这允许拥有 Instructor(讲师)角色的用户披露其他讲师课程中所注册学生的姓名和电子邮件地址。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MasterStudy LMS WordPress Plugin | 3.6.2 ~ 3.7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88994 | 6.6 MEDIUM | All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block Attributes |
| CVE-2026-79713 | 6.5 MEDIUM | Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tracking Paramet |
| CVE-2026-90977 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison |
| CVE-2026-86796 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hi |
| CVE-2026-86800 | 5.3 MEDIUM | WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Comp |
| CVE-2026-90976 | 5.3 MEDIUM | Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled |
| CVE-2026-85350 | UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought Together | |
| CVE-2026-84902 | King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Catalog Import | |
| CVE-2026-85127 | VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment | |
| CVE-2026-87767 | WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url | |
| CVE-2026-85123 | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login For | |
| CVE-2026-85009 | RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via P | |
| CVE-2026-85122 | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Confusion | |
| CVE-2026-84903 | King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Disclosure via kng | |
| CVE-2026-84904 | King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization via Image Opti | |
| CVE-2026-81810 | All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalation to Admin v | |
| CVE-2026-81340 | MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR | |
| CVE-2026-84738 | AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE | |
| CVE-2026-87770 | Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via product | |
| CVE-2026-87775 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet