WordPress security by component
Masteriyo LMS
Plugin description
Masteriyo LMS provides tools for creating and managing online courses, lessons, quizzes, students, and learning progress.
Masteriyo LMS (masteriyo-lms) is a WordPress plugin with 7 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.9.
Plugin slug:
masteriyo-lmsLatest vulnerability
CVE-2026-82851: Masteriyo instructors can download private posts they do not own
Masteriyo LMS from 1.14.0 through versions before 3.4.1 fails to verify ownership or restrict record type in a download flow. An instructor can request arbitrary posts and retrieve their full content and metadata, including another instructor's private or draft courses. The authoritative export does not identify the endpoint, record parameter, download format, or other exposed post types.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-82851
Masteriyo instructors can download private posts they do not own
Masteriyo LMS from 1.14.0 through versions before 3.4.1 fails to verify ownership or restrict record type in a download flow. An instructor can request arbitrary posts and retrieve their full content and metadata, including another instructor's private or draft courses. The authoritative export does not identify the endpoint, record parameter, download format, or other exposed post types.
|
3.4.1 |
CVE2.7
NVDPending
|
| Sep 12, 2026 |
CVE-2026-82847
Masteriyo course fields let instructors target administrators with XSS
Masteriyo LMS before 3.4.1 fails to sanitize and escape a course field before displaying it in the course editor. An instructor can store JavaScript in that field; it executes for a higher-privileged user such as an administrator who opens the course editor. The authoritative export does not identify the field, save endpoint, or output context.
|
3.4.1 |
CVE6.8
NVDPending
|
| Sep 12, 2026 |
CVE-2026-82845
Masteriyo LMS permits low-privilege object injection and code execution
Masteriyo LMS before 3.4.1 deserializes attacker-controlled metadata when it is read back. A minimally privileged account can inject a PHP object and use a class bundled with the plugin to write and execute arbitrary server-side code; an unauthenticated variant provides arbitrary file write. The authoritative export does not identify the metadata key, write endpoint, or triggering read path.
|
3.4.1 |
CVE9.9
NVDPending
|
| Sep 09, 2026 |
CVE-2026-82848
Masteriyo LMS exposes learner enrolment records without authorization
Masteriyo LMS versions 1.3.1 to before 3.4.0 return course-enrolment records through the REST API without authorization. Unauthenticated callers can enumerate sequential record IDs to read learner enrolment status, timestamps, and course progress. A related missing check lets enrolled users read other learners' records.
|
3.4.0 |
CVE5.3
NVDPending
|
| Sep 05, 2026 |
CVE-2026-82846
Masteriyo LMS permits course-author stored XSS
Masteriyo LMS 1.18.0 through 3.3.x does not adequately sanitize and escape course settings before rendering them on a public page. A user with the plugin's course-author role can store script that executes for any visitor viewing the affected course, including an Administrator.
|
3.4.0 |
CVE6.8
NVDPending
|
| Jul 27, 2026 |
CVE-2026-13332
Masteriyo LMS AJAX action permits forced logout of arbitrary users
Masteriyo LMS before 2.3.1 exposes an AJAX session-clear action without correctly authenticating the requester or authorizing the target account. An unauthenticated attacker can force any user, including an administrator, out of WordPress by submitting that user's target identifier to the vulnerable action.
|
2.3.1 |
CVE9.1
NVDPending
|
| Jun 25, 2026 |
CVE-2026-10824
Masteriyo LMS: A security weakness
Masteriyo LMS is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.2.1.
|
2.2.1 |
CVE6.5
NVDPending
|