Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Masteriyo LMS - Security Vulnerability (CVE-2026-82850)
The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed list of question types, so the answers to every other type are returned in full to anyone able to view the questions.
CVE-2026-82850
Masteriyo LMS - Security Vulnerability (CVE-2026-82849)
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.
CVE-2026-82849
Masteriyo LMS - Security Vulnerability (CVE-2026-82845)
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
CVE-2026-82845
Masteriyo LMS - Security Vulnerability (CVE-2026-82847)
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
CVE-2026-82847
Masteriyo LMS - Security Vulnerability (CVE-2026-82851)
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.
CVE-2026-82851
Masteriyo - LMS - Security Vulnerability (CVE-2026-62132)
Subscriber Broken Access Control in Masteriyo - LMS
CVE-2026-62132
Masteriyo - LMS - Security Vulnerability (CVE-2026-62107)
Unauthenticated PHP Object Injection in Masteriyo - LMS
CVE-2026-62107
Masteriyo LMS - Security Vulnerability (CVE-2026-82848)
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.
CVE-2026-82848
Masteriyo LMS - Broken Access Control (CVE-2026-8279)
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student.
CVE-2026-8279
Masteriyo LMS - Cross-Site Scripting (XSS) (CVE-2026-82846)
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.
CVE-2026-82846
Masteriyo - LMS - Arbitrary File Upload (CVE-2026-73996)
Unauthenticated Arbitrary File Upload in Masteriyo - LMS
CVE-2026-73996
Masteriyo LMS - Cross-Site Scripting (XSS) (CVE-2026-19712)
The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators. This affects default single-site installations. Sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there.
CVE-2026-19712
Masteriyo LMS - Security Vulnerability (CVE-2026-13332)
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.
CVE-2026-13332
Masteriyo - LMS - Cross-Site Scripting (XSS) (CVE-2026-59513)
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS
CVE-2026-59513
Masteriyo LMS - Broken Access Control (CVE-2026-11773)
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with student-level access and above, to modify the description (post content) of arbitrary course announcements authored by instructors or administrators.
CVE-2026-11773
Masteriyo LMS - Security Vulnerability (CVE-2026-10824)
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.
CVE-2026-10824
Masteriyo - LMS - Broken Access Control (CVE-2026-39524)
Unauthenticated Broken Access Control in Masteriyo - LMS
CVE-2026-39524
Masteriyo LMS - Broken Access Control (CVE-2026-5167)
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the handle_webhook() function. The webhook endpoint processes unauthenticated requests and only performs signature verification if both the webhook_secret setting is configured AND the HTTP_STRIPE_SIGNATURE header is present. Since webhook_secret defaults to an empty string, the webhook processes attacker-controlled JSON payloads without any verification. This makes it possible for unauthenticated attackers to…
CVE-2026-5167
Masteriyo LMS - Privilege Escalation (CVE-2026-4484)
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator.
CVE-2026-4484
Masteriyo LMS - Broken Access Control (CVE-2024-10008)
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authenticated attackers, with student-level access and above, to modify the roles of arbitrary users. As a result, attackers can escalate their privileges to the Administrator and demote existing administrators to students.
CVE-2024-10008