WordPress 插件 MasterStudy LMS 在 1.9 至 3.7.50 版本中存在安全漏洞。该漏洞允许任何成员将自己注册到其会员计划未涵盖的限制性付费课程,且不受其会员计划所允许的课程数量限制。具体来说,插件没有验证用户请求注册的课程是否在其会员计划范围内,也未验证用户提交的计划标识符是否为其实际持有的有效计划,从而导致用户能够绕过权限控制,非法访问付费内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MasterStudy LMS | 1.9 ~ 3.7.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80514 | 5.3 MEDIUM | wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass |
| CVE-2026-86837 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
| CVE-2026-78394 | Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter | |
| CVE-2026-78397 | Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation | |
| CVE-2026-78393 | Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb |
No comments yet