Payment Processing Flaw in MasterStudy LMS Plugin for WordPress
CVE-2026-81026
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 August 2026
Badges
What is CVE-2026-81026?
The MasterStudy LMS WordPress Plugin, prior to version 3.7.40, contains a critical vulnerability where payment notifications are not adequately verified. This flaw allows unauthenticated users to mark full-price orders as completed without proper validation of payment details like amount, receiver, or currency. Consequently, attackers can exploit this weakness to gain unauthorized access to premium content by exploiting a minimal payment, significantly undermining the security and integrity of the e-learning platform.
Affected Version(s)
MasterStudy LMS WordPress Plugin 0 < 3.7.40
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.