← WordPress Vulnerabilities
WordPress security by component

Masteriyo LMS

Masteriyo LMS provides tools for creating and managing online courses, lessons, quizzes, students, and learning progress.

Masteriyo LMS (masteriyo-lms) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.9.

Plugin slug: masteriyo-lms

CVE-2026-82851: Masteriyo instructors can download private posts they do not own

Masteriyo LMS from 1.14.0 through versions before 3.4.1 fails to verify ownership or restrict record type in a download flow. An instructor can request arbitrary posts and retrieve their full content and metadata, including another instructor's private or draft courses. The authoritative export does not identify the endpoint, record parameter, download format, or other exposed post types.

PublishedSep 12, 2026
Known safe version3.4.1
Published vulnerabilities for masteriyo-lms
Safe version
Sep 12, 2026 CVE-2026-82851
Masteriyo instructors can download private posts they do not own
Masteriyo LMS from 1.14.0 through versions before 3.4.1 fails to verify ownership or restrict record type in a download flow. An instructor can request arbitrary posts and retrieve their full content and metadata, including another instructor's private or draft courses. The authoritative export does not identify the endpoint, record parameter, download format, or other exposed post types.
3.4.1
CVE2.7
NVDPending
Sep 12, 2026 CVE-2026-82847
Masteriyo course fields let instructors target administrators with XSS
Masteriyo LMS before 3.4.1 fails to sanitize and escape a course field before displaying it in the course editor. An instructor can store JavaScript in that field; it executes for a higher-privileged user such as an administrator who opens the course editor. The authoritative export does not identify the field, save endpoint, or output context.
3.4.1
CVE6.8
NVDPending
Sep 12, 2026 CVE-2026-82845
Masteriyo LMS permits low-privilege object injection and code execution
Masteriyo LMS before 3.4.1 deserializes attacker-controlled metadata when it is read back. A minimally privileged account can inject a PHP object and use a class bundled with the plugin to write and execute arbitrary server-side code; an unauthenticated variant provides arbitrary file write. The authoritative export does not identify the metadata key, write endpoint, or triggering read path.
3.4.1
CVE9.9
NVDPending
Sep 09, 2026 CVE-2026-82848
Masteriyo LMS exposes learner enrolment records without authorization
Masteriyo LMS versions 1.3.1 to before 3.4.0 return course-enrolment records through the REST API without authorization. Unauthenticated callers can enumerate sequential record IDs to read learner enrolment status, timestamps, and course progress. A related missing check lets enrolled users read other learners' records.
3.4.0
CVE5.3
NVDPending
Sep 05, 2026 CVE-2026-82846
Masteriyo LMS permits course-author stored XSS
Masteriyo LMS 1.18.0 through 3.3.x does not adequately sanitize and escape course settings before rendering them on a public page. A user with the plugin's course-author role can store script that executes for any visitor viewing the affected course, including an Administrator.
3.4.0
CVE6.8
NVDPending
Jul 27, 2026 CVE-2026-13332
Masteriyo LMS AJAX action permits forced logout of arbitrary users
Masteriyo LMS before 2.3.1 exposes an AJAX session-clear action without correctly authenticating the requester or authorizing the target account. An unauthenticated attacker can force any user, including an administrator, out of WordPress by submitting that user's target identifier to the vulnerable action.
2.3.1
CVE9.1
NVDPending
Jun 25, 2026 CVE-2026-10824
Masteriyo LMS: A security weakness
Masteriyo LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.2.1.
2.2.1
CVE6.5
NVDPending