Filtered by vendor Masteriyo
Subscriptions
Filtered by product Masteriyo
Subscriptions
Total
15 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-82846 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-09-07 | 6.8 Medium |
| The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. | ||||
| CVE-2026-73996 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | ||||
| CVE-2026-19712 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-17 | 6.1 Medium |
| The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators. This affects default single-site installations. Sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there. | ||||
| CVE-2026-59513 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-02 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | ||||
| CVE-2026-65463 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-08-02 | 5.4 Medium |
| Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | ||||
| CVE-2026-13332 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-07-28 | 9.1 Critical |
| The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators. | ||||
| CVE-2026-10824 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-06-25 | 6.5 Medium |
| The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records. | ||||
| CVE-2025-64270 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-04-24 | 6.5 Medium |
| Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3. | ||||
| CVE-2025-54699 | 2 Masteriyo, Wordpress | 2 Masteriyo, Wordpress | 2026-04-23 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3. | ||||
| CVE-2024-43239 | 1 Masteriyo | 1 Masteriyo | 2026-04-23 | 4.3 Medium |
| Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. | ||||
| CVE-2024-43159 | 1 Masteriyo | 1 Masteriyo | 2026-04-23 | 5.3 Medium |
| Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6. | ||||
| CVE-2024-43158 | 1 Masteriyo | 1 Masteriyo | 2026-04-23 | 7.5 High |
| Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. | ||||
| CVE-2024-10000 | 1 Masteriyo | 1 Masteriyo | 2026-04-08 | 6.4 Medium |
| The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with student-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2024-10008 | 1 Masteriyo | 1 Masteriyo | 2026-04-08 | 8.8 High |
| The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authenticated attackers, with student-level access and above, to modify the roles of arbitrary users. As a result, attackers can escalate their privileges to the Administrator and demote existing administrators to students. | ||||
| CVE-2024-24882 | 2 Masteriyo, Themegrill | 2 Masteriyo, Masteriyo | 2026-04-01 | 9.8 Critical |
| Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2. | ||||
Page 1 of 1.