plugin

Learning Management System Vulnerabilities

35 known security issues reported for the Learning Management System WordPress plugin. Most recent disclosed Aug 20, 2026.

2 critical 4 high 17 medium

Running Learning Management System on your site? Check whether your installed version is affected.

Scan your site free

Masteriyo LMS – LMS Course Builder, Quizzes & Certificates < 2.3.3 - Authenticated (Custom Role+) Stored Cross-Site Scripting

medium

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 2.3.3. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom role-level access and above, t...

CVSS:
6.4
Affected:
up to 2.3.3
Fixed in:
2.3.3
Disclosed:
Aug 20, 2026

CVE-2026-19712 on NVD →

Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.2 - Unauthenticated Arbitrary File Upload

critical

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's serve...

CVSS:
9.8
Affected:
up to 2.3.2
Fixed in:
2.3.3
Disclosed:
Aug 18, 2026

CVE-2026-73996 on NVD →

Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.1 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above...

CVSS:
4.3
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jul 22, 2026

CVE-2026-65463 on NVD →

Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.3.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
6.4
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Jul 21, 2026

CVE-2026-59513 on NVD →

Masteriyo LMS <= 2.3.0 - Missing Authorization to Unauthenticated User Session Termination

medium

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to terminate user sessions.

CVSS:
5.3
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Jul 6, 2026

CVE-2026-13332 on NVD →

Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification

medium

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with...

CVSS:
4.3
Affected:
up to 2.2.1
Fixed in:
2.3.0
Disclosed:
Jun 26, 2026

CVE-2026-11773 on NVD →

Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation

high

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges.

CVSS:
8.8
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Jun 8, 2026

CVE-2026-49111 on NVD →

Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Course Progress Disclosure and Deletion

medium

The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 2.2.0. This is due to missing authentication and ownership checks in the CourseProgressItemsController permission callback functions. This makes it possible for unauthenticated attackers to view or delete cours...

CVSS:
5.3
Affected:
up to 2.2.0
Fixed in:
2.2.1
Disclosed:
Jun 4, 2026

CVE-2026-10824 on NVD →

Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.1.8 - Missing Authorization

medium

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.1.8
Fixed in:
2.1.9
Disclosed:
May 28, 2026

CVE-2026-42743 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 - Missing Authorization

medium

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.1.5
Fixed in:
2.1.6
Disclosed:
Apr 8, 2026

CVE-2026-39524 on NVD →

Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint

medium

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification in the handle_webhook() function. The webhook endpoint process...

CVSS:
5.3
Affected:
up to 2.1.7
Fixed in:
2.1.8
Disclosed:
Apr 7, 2026

CVE-2026-5167 on NVD →

Masteriyo - LMS - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability

high

Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator vulnerability

CVSS:
8.8
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Mar 30, 2026

Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

high

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with...

CVSS:
8.8
Affected:
up to 2.1.6
Fixed in:
2.1.7
Disclosed:
Mar 25, 2026

CVE-2026-4484 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] <= 2.0.3 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64270 on NVD →

Masteriyo - LMS <= 2.0.3 - Authenticated (Subscriber+) Sensitive Information Exposure

medium

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuratio...

CVSS:
4.3
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Nov 30, 2025

CVE-2025-64270 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.18.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS allows Stored XSS. This issue affects Masteriyo - LMS: from n/a through 1.18.3.

Affected:
up to 1.18.4
Fixed in:
1.18.4
Disclosed:
Aug 14, 2025

CVE-2025-54699 on NVD →

Masteriyo - LMS <= 1.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Masteriyo - LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.18.3
Fixed in:
1.18.4
Disclosed:
Jul 30, 2025

CVE-2025-54699 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.7.4

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo - LMS. Unauth access to course progress.This issue affects Masteriyo - LMS: from n/a through 1.7.3.

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
May 19, 2025

CVE-2024-33939 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.11.5

unknown

[en] Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.4.

Affected:
up to 1.11.5
Fixed in:
1.11.5
Disclosed:
Nov 1, 2024

CVE-2024-43158 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.12.0

unknown

[en] Missing Authorization vulnerability in Masteriyo Masteriyo - LMS allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masteriyo - LMS: from n/a through 1.11.6.

Affected:
up to 1.12.0
Fixed in:
1.12.0
Disclosed:
Nov 1, 2024

CVE-2024-43159 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.13.4

unknown

[en] The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for au...

Affected:
up to 1.13.4
Fixed in:
1.13.4
Disclosed:
Oct 29, 2024

CVE-2024-10008 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.13.4

unknown

[en] The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

Affected:
up to 1.13.4
Fixed in:
1.13.4
Disclosed:
Oct 29, 2024

CVE-2024-10000 on NVD →

Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Stored Cross-Site Scripting via Ask a Question Functionality

medium

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 1.13.3
Fixed in:
1.13.4
Disclosed:
Oct 28, 2024

CVE-2024-10000 on NVD →

Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation

high

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authent...

CVSS:
8.8
Affected:
up to 1.13.3
Fixed in:
1.13.4
Disclosed:
Oct 28, 2024

CVE-2024-10008 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.11.5

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Masteriyo Masteriyo - LMS.This issue affects Masteriyo - LMS: from n/a through 1.11.4.

Affected:
up to 1.11.5
Fixed in:
1.11.5
Disclosed:
Aug 18, 2024

CVE-2024-43239 on NVD →

Masteriyo - LMS <= 1.11.4 - Authenticated (Student+) Insecure Direct Object Reference

medium

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.11.4 due to missing validation on the 'course_id' user controlled key. This makes it possible for authenticated attackers, with student-lev...

CVSS:
5.3
Affected:
up to 1.11.4
Fixed in:
1.11.5
Disclosed:
Aug 12, 2024

CVE-2024-43239 on NVD →

Masteriyo - LMS <= 1.11.6 - Missing Authorization

medium

The Masteriyo - LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item() function in versions up to, and including, 1.11.6. This makes it possible for unauthenticated attackers to see courses they should not have access to.

CVSS:
5.3
Affected:
up to 1.11.6
Fixed in:
1.12.0
Disclosed:
Aug 7, 2024

CVE-2024-43159 on NVD →

Masteriyo - LMS <= 1.11.4 - Missing Authorization

medium

The Masteriyo - LMS plugin for WordPress is vulnerable to unauthorized access of dat due to a missing capability check on several REST API endpoints in versions up to, and including, 1.11.4. This makes it possible for unauthenticated attackers to view password protected content.

CVSS:
5.3
Affected:
up to 1.11.4
Fixed in:
1.11.5
Disclosed:
Aug 7, 2024

CVE-2024-43158 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.7.3

unknown

[en] Improper Privilege Management vulnerability in Masteriyo LMS allows Privilege Escalation.This issue affects LMS: from n/a through 1.7.2.

Affected:
up to 1.7.3
Fixed in:
1.7.3
Disclosed:
May 17, 2024

CVE-2024-24882 on NVD →

Masteriyo - LMS <= 1.7.3 - Insecure Direct Object Reference

medium

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.3 via the REST API due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view other...

CVSS:
5.3
Affected:
up to 1.7.3
Fixed in:
1.7.4
Disclosed:
Apr 30, 2024

CVE-2024-33939 on NVD →

Masteriyo - LMS <= 1.7.2 - Unauthenticated Privilege Escalation

critical

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_logged_in_user() function in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to elevate their pr...

CVSS:
9.8
Affected:
up to 1.7.2
Fixed in:
1.7.3
Disclosed:
Apr 5, 2024

CVE-2024-24882 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.6.8

unknown

[en] The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Jul 31, 2023

CVE-2023-3345 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.6.8

unknown

Update the WordPress Masteriyo - LMS plugin to the latest available version (at least 1.6.8). Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress Masteriyo - LMS Plugin. This vulnerability has been fixed in version 1.6.8.

Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Jul 6, 2023

Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure

medium

The Masteriyo - LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.7 via the 'get_item' REST callback. This can allow authenticated attackers to extract sensitive data including user metadata.

CVSS:
6.5
Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Jul 3, 2023

CVE-2023-3345 on NVD →

Masteriyo LMS – Online Course Builder for eLearning, LMS &amp; Education [learning-management-system] < 1.6.8

unknown

The Masteriyo - LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.7 via the 'get_item' REST callback. This can allow authenticated attackers to extract sensitive data including user metadata.

Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Jul 3, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database