Masteriyo LMS – LMS Course Builder, Quizzes & Certificates < 2.3.3 - Authenticated (Custom Role+) Stored Cross-Site Scripting
medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 2.3.3. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom role-level access and above, t...
- CVSS:
- 6.4
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Aug 20, 2026
CVE-2026-19712 on NVD →
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.2 - Unauthenticated Arbitrary File Upload
critical
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's serve...
- CVSS:
- 9.8
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.3
- Disclosed:
- Aug 18, 2026
CVE-2026-73996 on NVD →
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.1 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above...
- CVSS:
- 4.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jul 22, 2026
CVE-2026-65463 on NVD →
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 21, 2026
CVE-2026-59513 on NVD →
Masteriyo LMS <= 2.3.0 - Missing Authorization to Unauthenticated User Session Termination
medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to terminate user sessions.
- CVSS:
- 5.3
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 6, 2026
CVE-2026-13332 on NVD →
Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 2.2.1
- Fixed in:
- 2.3.0
- Disclosed:
- Jun 26, 2026
CVE-2026-11773 on NVD →
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation
high
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges.
- CVSS:
- 8.8
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 8, 2026
CVE-2026-49111 on NVD →
Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Course Progress Disclosure and Deletion
medium
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.2.0. This is due to missing authentication and ownership checks in the CourseProgressItemsController permission callback functions. This makes it possible for unauthenticated attackers to view or delete cours...
- CVSS:
- 5.3
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.1
- Disclosed:
- Jun 4, 2026
CVE-2026-10824 on NVD →
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.1.8 - Missing Authorization
medium
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- May 28, 2026
CVE-2026-42743 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 - Missing Authorization
medium
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.5
- Fixed in:
- 2.1.6
- Disclosed:
- Apr 8, 2026
CVE-2026-39524 on NVD →
Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint
medium
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the handle_webhook() function. The webhook endpoint process...
- CVSS:
- 5.3
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.8
- Disclosed:
- Apr 7, 2026
CVE-2026-5167 on NVD →
Masteriyo - LMS - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability
high
Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability
- CVSS:
- 8.8
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Mar 30, 2026
Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator
high
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Mar 25, 2026
CVE-2026-4484 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] <= 2.0.3 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.
- Affected:
- up to 2.0.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-64270 on NVD →
Masteriyo - LMS <= 2.0.3 - Authenticated (Subscriber+) Sensitive Information Exposure
medium
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuratio...
- CVSS:
- 4.3
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Nov 30, 2025
CVE-2025-64270 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.18.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS allows Stored XSS. This issue affects Masteriyo - LMS: from n/a through 1.18.3.
- Affected:
- up to 1.18.4
- Fixed in:
- 1.18.4
- Disclosed:
- Aug 14, 2025
CVE-2025-54699 on NVD →
Masteriyo - LMS <= 1.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Masteriyo - LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 1.18.3
- Fixed in:
- 1.18.4
- Disclosed:
- Jul 30, 2025
CVE-2025-54699 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.7.4
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo - LMS. Unauth access to course progress.This issue affects Masteriyo - LMS: from n/a through 1.7.3.
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- May 19, 2025
CVE-2024-33939 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.11.5
unknown
[en] Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.4.
- Affected:
- up to 1.11.5
- Fixed in:
- 1.11.5
- Disclosed:
- Nov 1, 2024
CVE-2024-43158 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.12.0
unknown
[en] Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.6.
- Affected:
- up to 1.12.0
- Fixed in:
- 1.12.0
- Disclosed:
- Nov 1, 2024
CVE-2024-43159 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.13.4
unknown
[en] The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for au...
- Affected:
- up to 1.13.4
- Fixed in:
- 1.13.4
- Disclosed:
- Oct 29, 2024
CVE-2024-10008 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.13.4
unknown
[en] The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
- Affected:
- up to 1.13.4
- Fixed in:
- 1.13.4
- Disclosed:
- Oct 29, 2024
CVE-2024-10000 on NVD →
Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Stored Cross-Site Scripting via Ask a Question Functionality
medium
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 1.13.3
- Fixed in:
- 1.13.4
- Disclosed:
- Oct 28, 2024
CVE-2024-10000 on NVD →
Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation
high
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authent...
- CVSS:
- 8.8
- Affected:
- up to 1.13.3
- Fixed in:
- 1.13.4
- Disclosed:
- Oct 28, 2024
CVE-2024-10008 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.11.5
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Masteriyo Masteriyo - LMS.This issue affects Masteriyo - LMS: from n/a through 1.11.4.
- Affected:
- up to 1.11.5
- Fixed in:
- 1.11.5
- Disclosed:
- Aug 18, 2024
CVE-2024-43239 on NVD →
Masteriyo - LMS <= 1.11.4 - Authenticated (Student+) Insecure Direct Object Reference
medium
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.11.4 due to missing validation on the 'course_id' user controlled key. This makes it possible for authenticated attackers, with student-lev...
- CVSS:
- 5.3
- Affected:
- up to 1.11.4
- Fixed in:
- 1.11.5
- Disclosed:
- Aug 12, 2024
CVE-2024-43239 on NVD →
Masteriyo - LMS <= 1.11.6 - Missing Authorization
medium
The Masteriyo - LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item() function in versions up to, and including, 1.11.6. This makes it possible for unauthenticated attackers to see courses they should not have access to.
- CVSS:
- 5.3
- Affected:
- up to 1.11.6
- Fixed in:
- 1.12.0
- Disclosed:
- Aug 7, 2024
CVE-2024-43159 on NVD →
Masteriyo - LMS <= 1.11.4 - Missing Authorization
medium
The Masteriyo - LMS plugin for WordPress is vulnerable to unauthorized access of dat due to a missing capability check on several REST API endpoints in versions up to, and including, 1.11.4. This makes it possible for unauthenticated attackers to view password protected content.
- CVSS:
- 5.3
- Affected:
- up to 1.11.4
- Fixed in:
- 1.11.5
- Disclosed:
- Aug 7, 2024
CVE-2024-43158 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.7.3
unknown
[en] Improper Privilege Management vulnerability in Masteriyo LMS allows Privilege Escalation.This issue affects LMS: from n/a through 1.7.2.
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- May 17, 2024
CVE-2024-24882 on NVD →
Masteriyo - LMS <= 1.7.3 - Insecure Direct Object Reference
medium
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.3 via the REST API due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view other...
- CVSS:
- 5.3
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.4
- Disclosed:
- Apr 30, 2024
CVE-2024-33939 on NVD →
Masteriyo - LMS <= 1.7.2 - Unauthenticated Privilege Escalation
critical
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_logged_in_user() function in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to elevate their pr...
- CVSS:
- 9.8
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.3
- Disclosed:
- Apr 5, 2024
CVE-2024-24882 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.6.8
unknown
[en] The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jul 31, 2023
CVE-2023-3345 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.6.8
unknown
Update the WordPress Masteriyo - LMS plugin to the latest available version (at least 1.6.8).
Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress Masteriyo - LMS Plugin. This vulnerability has been fixed in version 1.6.8.
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jul 6, 2023
Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure
medium
The Masteriyo - LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.7 via the 'get_item' REST callback. This can allow authenticated attackers to extract sensitive data including user metadata.
- CVSS:
- 6.5
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jul 3, 2023
CVE-2023-3345 on NVD →
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education [learning-management-system] < 1.6.8
unknown
The Masteriyo - LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.7 via the 'get_item' REST callback. This can allow authenticated attackers to extract sensitive data including user metadata.
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jul 3, 2023