VYPR

Masteriyo Lms

by WordPress

CVEs (23)

  • CVE-2026-82845CriSep 12, 2026
    risk 0.64cvss 9.9epss 0.01

    The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with…

  • CVE-2026-73996CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

  • CVE-2026-62107HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

  • CVE-2024-10008HigOct 29, 2024
    risk 0.57cvss 8.8epss 0.01

    The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including,…

  • CVE-2026-4484HigMar 26, 2026
    risk 0.50cvss 8.8epss 0.01

    The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it…

  • CVE-2026-82847MedSep 12, 2026
    risk 0.44cvss 6.8epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as…

  • CVE-2026-82846MedSep 5, 2026
    risk 0.44cvss 6.8epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of…

  • CVE-2025-64270MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.

  • CVE-2025-54699MedAug 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3.

  • CVE-2024-10000MedOct 29, 2024
    risk 0.42cvss 6.4epss 0.00

    The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping.…

  • CVE-2026-19712MedAug 16, 2026
    risk 0.40cvss 6.1epss 0.00

    The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any…

  • CVE-2026-62132MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.

  • CVE-2026-82848MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking…

  • CVE-2026-8279MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for…

  • CVE-2026-82850MedSep 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that…

  • CVE-2026-82849MedSep 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check…

  • CVE-2026-5167MedApr 8, 2026
    risk 0.27cvss 5.3epss 0.00

    The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the…

  • CVE-2026-82851LowSep 12, 2026
    risk 0.18cvss 2.7epss 0.00

    The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors'…

  • CVE-2026-13332CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.00

    The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including…

  • CVE-2026-65463MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

Page 1 of 2