← WordPress Vulnerabilities
WordPress security by component

Masteriyo - LMS

Masteriyo - LMS is a WordPress component with 14 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: learning-management-system

CVE-2026-65463: Masteriyo - LMS: A security weakness

Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.3.1.

PublishedJul 23, 2026
Known safe version2.3.2
Safe version
Jul 23, 2026 CVE-2026-65463
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.3.1.
2.3.2
CVE5.4
NVDPending
Jul 23, 2026 CVE-2026-59513
Masteriyo - LMS: Cross-site scripting
Masteriyo - LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.3.0.
2.3.1
CVE6.5
NVDPending
Jun 27, 2026 CVE-2026-11773
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates: A security weakness
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.2.1.
> 2.2.1
CVE4.3
NVDPending
Jun 15, 2026 CVE-2026-42743
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.1.8.
2.1.9
CVE6.5
NVDPending
Jun 15, 2026 CVE-2026-39524
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.1.5.
2.1.6
CVE7.5
NVDPending
Jun 15, 2026 CVE-2026-49111
Masteriyo - LMS: Privilege escalation or authentication bypass
Masteriyo - LMS is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.2.0.
2.2.1
CVE8.8
NVDPending
Apr 08, 2026 CVE-2026-5167
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: A security weakness
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.7.
> 2.1.7
CVE5.3
NVDPending
Mar 26, 2026 CVE-2026-4484
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: Privilege escalation or authentication bypass
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.1.6.
> 2.1.6
CVE8.8
NVDPending
Dec 18, 2025 CVE-2025-64270
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 14, 2025 CVE-2025-54699
Masteriyo - LMS: Cross-site scripting
Masteriyo - LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 29, 2024 CVE-2024-10008
Masteriyo LMS – eLearning and Online Course Builder for: A security weakness
Masteriyo LMS – eLearning and Online Course Builder for is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD6.5
Oct 29, 2024 CVE-2024-10000
Masteriyo LMS – eLearning and Online Course Builder for: Cross-site scripting
Masteriyo LMS – eLearning and Online Course Builder for is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2024-24882
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Feb 07, 2022 CVE-2021-25029
CLUEVO LMS, E-Learning Platform: Cross-site scripting
CLUEVO LMS, E-Learning Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8