← WordPress Vulnerabilities
WordPress security by component

Masteriyo - LMS

Masteriyo - LMS provides tools for creating and managing online courses, lessons, quizzes, instructors, students, and learning content.

Masteriyo - LMS (learning-management-system) is a WordPress plugin with 19 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.

Plugin slug: learning-management-system

CVE-2026-62132: Masteriyo exposes a low-privilege authorization flaw

Masteriyo - LMS through 3.4.0 has a broken-access-control flaw. The vector requires no user interaction and rates integrity impact as low, but the endpoint, action, parameter, protected object, and resulting change are not disclosed.

PublishedSep 11, 2026
Known safe version3.4.1
Published vulnerabilities for learning-management-system
Safe version
Sep 11, 2026 CVE-2026-62132
Masteriyo exposes a low-privilege authorization flaw
Masteriyo - LMS through 3.4.0 has a broken-access-control flaw. The vector requires no user interaction and rates integrity impact as low, but the endpoint, action, parameter, protected object, and resulting change are not disclosed.
3.4.1
CVE5.3
NVDPending
Sep 11, 2026 CVE-2026-62107
Masteriyo exposes a high-impact PHP object injection flaw
Masteriyo - LMS through 3.4.0 permits PHP object injection. The vector requires no user interaction and rates confidentiality, integrity, and availability impact as high, but the endpoint, parameter, deserialization operation, gadget chain, and exact post-injection effect are not disclosed.
3.4.1
CVE8.8
NVDPending
Sep 07, 2026 CVE-2026-8279
Masteriyo LMS permits unauthenticated deletion of student course progress
Masteriyo LMS through 2.2.0 omits a capability check in CourseProgressItemsController::delete_item_permissions_check(). An unauthenticated request can therefore delete arbitrary course-progress records belonging to any student.
See mitigation notes
CVE5.3
NVDPending
Aug 18, 2026 CVE-2026-73996
Masteriyo - LMS: Dangerous file upload
Masteriyo - LMS is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through 2.3.2.
2.3.3
CVE9.8
NVDPending
Aug 16, 2026 CVE-2026-19712
Masteriyo instructor quiz content permits stored XSS
Masteriyo LMS before 2.3.3 allows an Instructor to store script-capable content in an affected quiz field. On a normal single-site installation, Masteriyo grants instructors unfiltered HTML, so the payload can execute when another user views the quiz. Multisite installations and sites defining DISALLOW_UNFILTERED_HTML are not affected by this specific path.
2.3.3
CVE6.1
NVDPending
Jul 23, 2026 CVE-2026-65463
Masteriyo - LMS: Broken access control
Masteriyo - LMS is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.3.1.
2.3.2
CVE5.4
NVDPending
Jul 23, 2026 CVE-2026-59513
Masteriyo - LMS: Cross-site scripting
Masteriyo - LMS is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.3.0.
2.3.1
CVE6.5
NVDPending
Jun 27, 2026 CVE-2026-11773
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates: A security weakness
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.2.1.
See mitigation notes
CVE4.3
NVDPending
Jun 15, 2026 CVE-2026-42743
Masteriyo - LMS: Privilege escalation or authentication bypass
Masteriyo - LMS is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.1.8.
2.1.9
CVE6.5
NVDPending
Jun 15, 2026 CVE-2026-39524
Masteriyo - LMS: Broken access control
Masteriyo - LMS is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.1.5.
2.1.6
CVE7.5
NVDPending
Jun 15, 2026 CVE-2026-49111
Masteriyo - LMS: Privilege escalation or authentication bypass
Masteriyo - LMS is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 2.2.0.
2.2.1
CVE8.8
NVDPending
Apr 08, 2026 CVE-2026-5167
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: A security weakness
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.1.7.
See mitigation notes
CVE5.3
NVDPending
Mar 26, 2026 CVE-2026-4484
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education: Privilege escalation or authentication bypass
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 2.1.6.
See mitigation notes
CVE8.8
NVDPending
Dec 18, 2025 CVE-2025-64270
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 14, 2025 CVE-2025-54699
Masteriyo - LMS: Cross-site scripting
Masteriyo - LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 29, 2024 CVE-2024-10008
Masteriyo LMS – eLearning and Online Course Builder for: A security weakness
Masteriyo LMS – eLearning and Online Course Builder for is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD6.5
Oct 29, 2024 CVE-2024-10000
Masteriyo LMS – eLearning and Online Course Builder for: Cross-site scripting
Masteriyo LMS – eLearning and Online Course Builder for is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 17, 2024 CVE-2024-24882
Masteriyo - LMS: A security weakness
Masteriyo - LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Feb 07, 2022 CVE-2021-25029
CLUEVO LMS, E-Learning Platform: Cross-site scripting
CLUEVO LMS, E-Learning Platform is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8