Masteriyo Lms
by WordPress
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82845 | Cri | 0.64 | 9.9 | 0.01 | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with… | ||
| CVE-2026-73996 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||
| CVE-2026-62107 | Hig | 0.57 | 8.8 | 0.01 | Sep 11, 2026 | Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | ||
| CVE-2024-10008 | Hig | 0.57 | 8.8 | 0.01 | Oct 29, 2024 | The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including,… | ||
| CVE-2026-4484 | Hig | 0.50 | 8.8 | 0.01 | Mar 26, 2026 | The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it… | ||
| CVE-2026-82847 | Med | 0.44 | 6.8 | 0.00 | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as… | ||
| CVE-2026-82846 | Med | 0.44 | 6.8 | 0.00 | Sep 5, 2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of… | ||
| CVE-2025-64270 | Med | 0.42 | 6.5 | 0.00 | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3. | ||
| CVE-2025-54699 | Med | 0.42 | 6.5 | 0.00 | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3. | ||
| CVE-2024-10000 | Med | 0.42 | 6.4 | 0.00 | Oct 29, 2024 | The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping.… | ||
| CVE-2026-19712 | Med | 0.40 | 6.1 | 0.00 | Aug 16, 2026 | The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any… | ||
| CVE-2026-62132 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | ||
| CVE-2026-82848 | Med | 0.34 | 5.3 | 0.00 | Sep 9, 2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking… | ||
| CVE-2026-8279 | Med | 0.34 | 5.3 | 0.00 | Sep 7, 2026 | The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for… | ||
| CVE-2026-82850 | Med | 0.28 | 4.3 | 0.00 | Sep 24, 2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that… | ||
| CVE-2026-82849 | Med | 0.28 | 4.3 | 0.00 | Sep 24, 2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check… | ||
| CVE-2026-5167 | Med | 0.27 | 5.3 | 0.00 | Apr 8, 2026 | The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the… | ||
| CVE-2026-82851 | Low | 0.18 | 2.7 | 0.00 | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors'… | ||
| CVE-2026-13332 | Cri | 0.00 | 9.1 | 0.00 | Jul 27, 2026 | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including… | ||
| CVE-2026-65463 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. |
- risk 0.64cvss 9.9epss 0.01
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with…
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
- risk 0.57cvss 8.8epss 0.01
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
- risk 0.57cvss 8.8epss 0.01
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including,…
- risk 0.50cvss 8.8epss 0.01
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it…
- risk 0.44cvss 6.8epss 0.00
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as…
- risk 0.44cvss 6.8epss 0.00
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of…
- risk 0.42cvss 6.5epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.
- risk 0.42cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3.
- risk 0.42cvss 6.4epss 0.00
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping.…
- risk 0.40cvss 6.1epss 0.00
The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any…
- risk 0.34cvss 5.3epss 0.00
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
- risk 0.34cvss 5.3epss 0.00
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking…
- risk 0.34cvss 5.3epss 0.00
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for…
- risk 0.28cvss 4.3epss 0.00
The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that…
- risk 0.28cvss 4.3epss 0.00
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check…
- risk 0.27cvss 5.3epss 0.00
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the…
- risk 0.18cvss 2.7epss 0.00
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors'…
- risk 0.00cvss 9.1epss 0.00
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including…
- risk 0.00cvss 5.4epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
Page 1 of 2