SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81026

MEDIUM · CVSS 4.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MasterStudy LMS WordPress Plugin prior to version 3.7.40 is vulnerable as it fails to properly validate payment notifications, enabling unauthenticated users to complete full-price orders for paid content by submitting minimal payment amounts. This flaw could lead to unauthorized access to premium content, posing a significant risk to educational institutions and businesses relying on this plugin for monetization. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential financial losses and protect content integrity.

CVE
CVE-2026-81026
Severity
MEDIUM
CVSS
4.8
EPSS
0.14%
WordPress

Original NVD Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.