SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81196

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The MasterStudy LMS WordPress plugin prior to version 3.7.46 is vulnerable due to inadequate verification of quiz question ownership, enabling instructors to access and read quiz questions, answers, and explanations created by other instructors. This could lead to unauthorized sharing of educational content and compromise the integrity of assessments. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-81196
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.