THREAT OPS › Threat News › [NVD] CVE-2026-81026 (MEDIUM 4.8) — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access t
[NVD] CVE-2026-81026 (MEDIUM 4.8) — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access t
CVE-2026-81026 CVSS: 4.8 MEDIUM Published: 2026-08-29T06:17:55.990
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.
Indicators of compromise
- CVE-2026-81026cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81026