WordPress security by component
Masteriyo - LMS
Plugin description
Masteriyo - LMS provides tools for creating and managing online courses, lessons, quizzes, instructors, students, and learning content.
Masteriyo - LMS (learning-management-system) is a WordPress plugin with 19 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
learning-management-systemLatest vulnerability
CVE-2026-62132: Masteriyo exposes a low-privilege authorization flaw
Masteriyo - LMS through 3.4.0 has a broken-access-control flaw. The vector requires no user interaction and rates integrity impact as low, but the endpoint, action, parameter, protected object, and resulting change are not disclosed.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62132
Masteriyo exposes a low-privilege authorization flaw
Masteriyo - LMS through 3.4.0 has a broken-access-control flaw. The vector requires no user interaction and rates integrity impact as low, but the endpoint, action, parameter, protected object, and resulting change are not disclosed.
|
3.4.1 |
CVE5.3
NVDPending
|
| Sep 11, 2026 |
CVE-2026-62107
Masteriyo exposes a high-impact PHP object injection flaw
Masteriyo - LMS through 3.4.0 permits PHP object injection. The vector requires no user interaction and rates confidentiality, integrity, and availability impact as high, but the endpoint, parameter, deserialization operation, gadget chain, and exact post-injection effect are not disclosed.
|
3.4.1 |
CVE8.8
NVDPending
|
| Sep 07, 2026 |
CVE-2026-8279
Masteriyo LMS permits unauthenticated deletion of student course progress
Masteriyo LMS through 2.2.0 omits a capability check in CourseProgressItemsController::delete_item_permissions_check(). An unauthenticated request can therefore delete arbitrary course-progress records belonging to any student.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 18, 2026 |
CVE-2026-73996
Masteriyo - LMS: Dangerous file upload
Masteriyo - LMS is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 2.3.2.
|
2.3.3 |
CVE9.8
NVDPending
|
| Aug 16, 2026 |
CVE-2026-19712
Masteriyo instructor quiz content permits stored XSS
Masteriyo LMS before 2.3.3 allows an Instructor to store script-capable content in an affected quiz field. On a normal single-site installation, Masteriyo grants instructors unfiltered HTML, so the payload can execute when another user views the quiz. Multisite installations and sites defining DISALLOW_UNFILTERED_HTML are not affected by this specific path.
|
2.3.3 |
CVE6.1
NVDPending
|
| Jul 23, 2026 |
CVE-2026-65463
Masteriyo - LMS: Broken access control
Masteriyo - LMS is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.3.1.
|
2.3.2 |
CVE5.4
NVDPending
|
| Jul 23, 2026 |
CVE-2026-59513
Masteriyo - LMS: Cross-site scripting
Masteriyo - LMS is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.3.0.
|
2.3.1 |
CVE6.5
NVDPending
|
| Jun 27, 2026 |
CVE-2026-11773
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates: A security weakness
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.2.1.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42743
Masteriyo - LMS: Privilege escalation or authentication bypass
Masteriyo - LMS is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.1.8.
|
2.1.9 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39524
Masteriyo - LMS: Broken access control
Masteriyo - LMS is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.1.5.
|
2.1.6 |
CVE7.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-49111
Masteriyo - LMS: Privilege escalation or authentication bypass
Masteriyo - LMS is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.2.0.
|
2.2.1 |
CVE8.8
NVDPending
|
| Apr 08, 2026 |
CVE-2026-5167
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: A security weakness
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.7.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 26, 2026 |
CVE-2026-4484
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: Privilege escalation or authentication bypass
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.1.6.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64270
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54699
Masteriyo - LMS: Cross-site scripting
Masteriyo - LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 29, 2024 |
CVE-2024-10008
Masteriyo LMS – eLearning and Online Course Builder for: A security weakness
Masteriyo LMS – eLearning and Online Course Builder for is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD6.5
|
| Oct 29, 2024 |
CVE-2024-10000
Masteriyo LMS – eLearning and Online Course Builder for: Cross-site scripting
Masteriyo LMS – eLearning and Online Course Builder for is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 17, 2024 |
CVE-2024-24882
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 07, 2022 |
CVE-2021-25029
CLUEVO LMS, E-Learning Platform: Cross-site scripting
CLUEVO LMS, E-Learning Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|