MasterStudy LMS <= 3.6.20 - Authenticated (Subscriber+) Race Condition to Multiple Reviews

2025-09-22 00:00
Bibek Dhakal

Vulnerability Overview

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 3.6.20. This makes it possible for authenticated attackers, with Subscriber-level access and above, to leave multiple reviews on a course.

Technical Analysis

REMEDIATION: Update to version 3.6.21, or a newer patched version --- IDENTIFIER: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C