Masteriyo Lms
by WordPress
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59513 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | ||
| CVE-2026-11773 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-10824 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records. |
- risk 0.00cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
- risk 0.00cvss 4.3epss 0.00
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 6.5epss 0.00
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.
Page 2 of 2