« Back to list

Masteriyo

Masteriyo LMS: vulnerabilities and CVEs

Masteriyo LMS has 15 published vulnerabilities, 15 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs15
Last 12 months15
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-82850Medium (4.3)0.18%—Sep 24, 2026
The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including…
CVE-2026-82849Medium (4.3)0.16%—Sep 24, 2026
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to…
CVE-2026-82851Low (2.7)0.30%—Sep 12, 2026
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and…
CVE-2026-82847Medium (6.8)0.43%—Sep 12, 2026
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site…
CVE-2026-82845Critical (9.9)0.64%—Sep 12, 2026
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP…
CVE-2026-82848Medium (5.3)0.32%—Sep 9, 2026
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment…
CVE-2026-8279Medium (5.3)0.40%—Sep 7, 2026
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions…
CVE-2026-82846Medium (6.8)0.43%—Sep 5, 2026
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored…
CVE-2026-19712Medium (6.1)0.25%—Aug 16, 2026
The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to…
CVE-2026-13332Critical (9.1)0.42%—Jul 27, 2026
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions…
CVE-2026-59513Medium (6.5)0.22%—Jul 23, 2026
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
CVE-2026-11773Medium (4.3)0.25%—Jun 27, 2026
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying…
CVE-2026-10824Medium (6.5)0.27%—Jun 25, 2026
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress…
CVE-2026-5167Medium (5.3)0.49%—Apr 8, 2026
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to…
CVE-2026-4484High (8.8)0.51%—Mar 26, 2026
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter1
  4. T1068 Exploitation for Privilege Escalation1
  5. T1078 Valid Accounts1
  6. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Masteriyo