THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-81026 (MEDIUM 4.8) — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access t

[NVD] CVE-2026-81026 (MEDIUM 4.8) — The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access t

mednvdPublished 2026-08-29

CVE-2026-81026 CVSS: 4.8 MEDIUM Published: 2026-08-29T06:17:55.990

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81026