CVE-2025-13766

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload or delete arbitrary media files, delete or modify posts, and create/manage course templates


We have discovered 1,571 live websites that are affected by CVE-2025-13766.

Run a Free Instant Scan




Affected Software

Product  Masterstudy LMS Learning Management System
Category Wordpress Plugins
Vulnerable Domains1,571 live websites (96% of Masterstudy LMS Learning Management System install base)
Vulnerable Versions
  • from 0 through 3.7.6
Vulnerable Versions Count113 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 6, 2026
  • Updated - Jan 6, 2026

Credits

  • thinnawarth mathuros (finder)

Website Distribution by Country

Number of websites using CVE-2025-13766
United States407 websites



Germany123 websites
France116 websites
Italy79 websites
GB74 websites
Cyprus72 websites
India65 websites
Spain63 websites
Brazil51 websites
Turkey27 websites

Website Distribution by TLD

Number of websites using CVE-2025-13766
.com702 websites
.org121 websites
.it56 websites
.com.br45 websites
.net42 websites
.de34 websites
.fr28 websites
.es26 websites
.co.uk23 websites
.nl22 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-13766

Top websites that are affected by CVE-2025-13766. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States**,***
*******.org United States***,***
**************.***.br Brazil***,***
***********.**.za South Africa***,***
***********.***.co Colombia***,***
*****.org United States***,***
************************.com GB***,***
*****.**************.com United States***,***
********.*******.***.cl Chile***,***
***.***************.eu Germany***,***
See full domain list

FAQ

CVE-2025-13766 is Missing Authorization in Masterstudy LMS Learning Management System
A total of 1,571 websites have been identified as vulnerable to CVE-2025-13766, based on global website indexing conducted by WebTechSurvey.
The Masterstudy LMS Learning Management System is affected by the CVE-2025-13766 vulnerability.
Masterstudy LMS Learning Management System versions up to and including 3.7.6 are vulnerable to CVE-2025-13766.