HomeWordPress vulnerabilitiesMasteriyo LMS
Masteriyo LMS vulnerabilities
Masteriyo LMS has 16 known vulnerabilities in this database. The most recent published record is dated 24 Sep 2026.
- Known vulnerabilities
- 16
- Active installs
- 6,000+
- Latest version
- 3.4.3
- Last updated
- 30 Sep 2026
- Most recent
- 24 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-82849 | Medium 4.3 | Before 3.4.2 | Fixed in 3.4.2 | 13 d ago |
| Sensitive data exposure CVE-2026-82850 | Medium 4.3 | Before 3.4.2 | Fixed in 3.4.2 | 13 d ago |
| PHP object injection CVE-2026-82845 | Critical 9.9 | Before 3.4.1 | Fixed in 3.4.1 | 12 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-82847 | Medium 6.8 | Before 3.4.1 | Fixed in 3.4.1 | 12 Sep 2026 |
| Broken access control CVE-2026-82851 | Low 2.7 | Before 3.4.1 | Fixed in 3.4.1 | 12 Sep 2026 |
| Broken access control CVE-2026-82848 | Medium 5.3 | Before 3.4.0 | Fixed in 3.4.0 | 9 Sep 2026 |
| Broken access control CVE-2026-8279 | Medium 5.3 | Up to 2.2.0 | Fixed in a later version (latest 3.4.3) | 7 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-82846 | Medium 6.8 | Before 3.4.0 | Fixed in 3.4.0 | 5 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-19712 | Medium 6.1 | Before 2.3.3 | Fixed in 2.3.3 | 16 Aug 2026 |
| Authentication bypass CVE-2026-13332 | Critical 9.1 | Before 2.3.1 | Fixed in 2.3.1 | 27 Jul 2026 |
| Broken access control CVE-2026-11773 | Medium 4.3 | Up to 2.2.1 | Fixed in a later version (latest 3.4.3) | 27 Jun 2026 |
| Security weakness CVE-2026-10824 | Medium 6.5 | Before 2.2.1 | Fixed in 2.2.1 | 25 Jun 2026 |
| Broken access control CVE-2026-5167 | Medium 5.3 | Up to 2.1.7 | Fixed in a later version (latest 3.4.3) | 8 Apr 2026 |
| Privilege escalation CVE-2026-4484 | High 8.8 | Up to 2.1.6 | Fixed in a later version (latest 3.4.3) | 26 Mar 2026 |
| Cross-site scripting (XSS) CVE-2024-10000 | Medium 6.4 | Before 1.13.4 | Fixed in 1.13.4 | 29 Oct 2024 |
| Broken access control CVE-2024-10008 | High 8.8 | Before 1.13.4 | Fixed in 1.13.4 | 29 Oct 2024 |
Read the published descriptions
- CVE-2026-82849, 24 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once. CVE record
- CVE-2026-82850, 24 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed list of question types, so the answers to every other type are returned in full to anyone able to view the questions. CVE record
- CVE-2026-82845, 12 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution. CVE record
- CVE-2026-82847, 12 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators. CVE record
- CVE-2026-82851, 12 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses. CVE record
- CVE-2026-82848, 9 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well. CVE record
- CVE-2026-8279, 7 Sep 2026
- The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student. CVE record
- CVE-2026-82846, 5 Sep 2026
- The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. CVE record
- CVE-2026-19712, 16 Aug 2026
- The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators. This affects default single-site installations. Sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there. CVE record
- CVE-2026-13332, 27 Jul 2026
- The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators. CVE record
- CVE-2026-11773, 27 Jun 2026
- The Masteriyo LMS - LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with student-level access and above, to modify the description (post content) of arbitrary course announcements authored by instructors or administrators. CVE record
- CVE-2026-10824, 25 Jun 2026
- The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records. CVE record
- CVE-2026-5167, 8 Apr 2026
- The Masteriyo LMS - Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the handle_webhook() function. The webhook endpoint processes unauthenticated requests and only performs signature verification if both the webhook_secret setting is configured AND the HTTP_STRIPE_SIGNATURE header is present. Since webhook_secret defaults to an empty string, the webhook processes attacker-controlled JSON payloads without any verification. This makes it possible for unauthenticated attackers to send fake Stripe webhook events with arbitrary order_id values in the metadata, mark any order as completed without payment, and gain unauthorized access to paid course content. CVE record
- CVE-2026-4484, 26 Mar 2026
- The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator. CVE record
- CVE-2024-10000, 29 Oct 2024
- The Masteriyo LMS - eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with student-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-10008, 29 Oct 2024
- The Masteriyo LMS - eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authenticated attackers, with student-level access and above, to modify the roles of arbitrary users. As a result, attackers can escalate their privileges to the Administrator and demote existing administrators to students. CVE record
What to do if you run Masteriyo LMS
If you run Masteriyo LMS, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Masteriyo LMS vulnerabilities
Free. We email you when a new vulnerability is published for Masteriyo LMS, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.