WordPress security by component
Masteriyo LMS
Plugin description
Masteriyo LMS is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.1.
Plugin slug:
masteriyo-lmsLatest vulnerability
CVE-2026-13332: Masteriyo LMS AJAX action permits forced logout of arbitrary users
Masteriyo LMS before 2.3.1 exposes an AJAX session-clear action without correctly authenticating the requester or authorizing the target account. An unauthenticated attacker can force any user, including an administrator, out of WordPress by submitting that user's target identifier to the vulnerable action. The CNA record does not disclose the AJAX action, target parameter or session-clearing function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-13332
Masteriyo LMS AJAX action permits forced logout of arbitrary users
Masteriyo LMS before 2.3.1 exposes an AJAX session-clear action without correctly authenticating the requester or authorizing the target account. An unauthenticated attacker can force any user, including an administrator, out of WordPress by submitting that user's target identifier to the vulnerable action. The CNA record does not disclose the AJAX action, target parameter or session-clearing function.
|
2.3.1 |
CVE9.1
NVDPending
|
| Jun 25, 2026 |
CVE-2026-10824
Masteriyo LMS: A security weakness
Masteriyo LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.2.1.
|
2.2.1 |
CVE6.5
NVDPending
|