The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
https://wpscan.com/vulnerability/513d2c6e-9b9e-432d-8106-47916252bd55/