← WordPress Vulnerabilities
WordPress security by component

Masteriyo LMS

Masteriyo LMS is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.1.

Plugin slug: masteriyo-lms

CVE-2026-13332: Masteriyo LMS AJAX action permits forced logout of arbitrary users

Masteriyo LMS before 2.3.1 exposes an AJAX session-clear action without correctly authenticating the requester or authorizing the target account. An unauthenticated attacker can force any user, including an administrator, out of WordPress by submitting that user's target identifier to the vulnerable action. The CNA record does not disclose the AJAX action, target parameter or session-clearing function.

PublishedJul 27, 2026
Known safe version2.3.1
Safe version
Jul 27, 2026 CVE-2026-13332
Masteriyo LMS AJAX action permits forced logout of arbitrary users
Masteriyo LMS before 2.3.1 exposes an AJAX session-clear action without correctly authenticating the requester or authorizing the target account. An unauthenticated attacker can force any user, including an administrator, out of WordPress by submitting that user's target identifier to the vulnerable action. The CNA record does not disclose the AJAX action, target parameter or session-clearing function.
2.3.1
CVE9.1
NVDPending
Jun 25, 2026 CVE-2026-10824
Masteriyo LMS: A security weakness
Masteriyo LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.2.1.
2.2.1
CVE6.5
NVDPending