Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | Masteriyo LMSAI | 24/9/2026 | 24/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed… | |
| Aplazada | Media (4.3) | 0.16% | — | Masteriyo LMSAI | 24/9/2026 | 24/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the… | |
| Aplazada | Baja (2.7) | 0.30% | — | Masteriyo LMSAI | 12/9/2026 | 14/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses. | |
| Aplazada | Media (6.8) | 0.43% | — | Masteriyo LMSAI | 12/9/2026 | 14/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators. | |
| Aplazada | Crítica (9.9) | 0.64% | — | Masteriyo LMSAI | 12/9/2026 | 14/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin… | |
| Aplazada | Media (5.3) | 0.32% | — | Masteriyo LMSAI | 9/9/2026 | 9/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets… | |
| Aplazada | Media (5.3) | 0.40% | — | Masteriyo LMSAI | 7/9/2026 | 8/9/2026 | The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Media (6.8) | 0.43% | — | Masteriyo LMSAI | 5/9/2026 | 8/9/2026 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a… | |
| Aplazada | Media (6.1) | 0.25% | — | Masteriyo LMSAI | 16/8/2026 | 26/8/2026 | The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Masteriyo LMSAI | 27/7/2026 | 27/7/2026 | The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators. | |
| Aplazada | Media (6.5) | 0.22% | — | Masteriyo LMSAI | 23/7/2026 | 23/7/2026 | Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Masteriyo LMSAI | 27/6/2026 | 29/6/2026 | The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.27% | — | Masteriyo LMSAI | 25/6/2026 | 25/6/2026 | The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records. | |
| Aplazada | Crítica (9.8) | 0.27% | — | Themeisle Masteriyo LMS PROAI | 2/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0. | |
| Aplazada | Media (5.3) | 0.49% | — | Masteriyo LMSAI | 8/4/2026 | 24/7/2026 | The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the handle_webhook() function. The webhook endpoint… | |
| Aplazada | Alta (8.8) | 0.51% | — | Masteriyo LMSAI | 26/3/2026 | 17/6/2026 | The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with… |