Masteriyo
Masteriyo LMS: vulnerabilities and CVEs
Masteriyo LMS has 15 published vulnerabilities, 15 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months15
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82850 | Medium (4.3) | 0.18% | — | Sep 24, 2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including… |
| CVE-2026-82849 | Medium (4.3) | 0.16% | — | Sep 24, 2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to… |
| CVE-2026-82851 | Low (2.7) | 0.30% | — | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and… |
| CVE-2026-82847 | Medium (6.8) | 0.43% | — | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site… |
| CVE-2026-82845 | Critical (9.9) | 0.64% | — | Sep 12, 2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP… |
| CVE-2026-82848 | Medium (5.3) | 0.32% | — | Sep 9, 2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment… |
| CVE-2026-8279 | Medium (5.3) | 0.40% | — | Sep 7, 2026 | The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions… |
| CVE-2026-82846 | Medium (6.8) | 0.43% | — | Sep 5, 2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored… |
| CVE-2026-19712 | Medium (6.1) | 0.25% | — | Aug 16, 2026 | The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to… |
| CVE-2026-13332 | Critical (9.1) | 0.42% | — | Jul 27, 2026 | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions… |
| CVE-2026-59513 | Medium (6.5) | 0.22% | — | Jul 23, 2026 | Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. |
| CVE-2026-11773 | Medium (4.3) | 0.25% | — | Jun 27, 2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying… |
| CVE-2026-10824 | Medium (6.5) | 0.27% | — | Jun 25, 2026 | The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress… |
| CVE-2026-5167 | Medium (5.3) | 0.49% | — | Apr 8, 2026 | The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to… |
| CVE-2026-4484 | High (8.8) | 0.51% | — | Mar 26, 2026 | The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.