CyberRota Analysis
AI-GeneratedThe MasterStudy LMS WordPress Plugin prior to version 3.7.40 is vulnerable as it fails to properly validate payment notifications, enabling unauthenticated users to complete full-price orders for paid content by submitting minimal payment amounts. This flaw could lead to unauthorized access to premium content, posing a significant risk to educational institutions and businesses relying on this plugin for monetization. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential financial losses and protect content integrity.
Original NVD Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.