PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11773 masteriyo CVE debrief

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This vulnerability allows authenticated attackers, with student-level access and above, to modify the description of arbitrary course announcements authored by instructors or administrators. The plugin fails to properly verify that a user is authorized to perform an action, leading to this security issue. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The CVE record was published on June 27, 2026, and last modified on June 29, 2026.

Vendor
masteriyo
Product
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-27
Original CVE updated
2026-06-29
Advisory published
2026-06-27
Advisory updated
2026-06-29

Who should care

Administrators and users of the Masteriyo LMS plugin for WordPress should be aware of this vulnerability and take necessary actions to protect their sites. Authenticated attackers with student-level access and above can exploit this vulnerability to modify course announcements. It is essential to update the plugin to a patched version as soon as possible.

Technical summary

The Masteriyo LMS plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows authenticated attackers with student-level access and above to modify the description of arbitrary course announcements. The vulnerability exists in all versions up to and including 2.2.1. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N.

Defensive priority

Medium priority should be given to patching this vulnerability, as it allows for modification of course announcements by authenticated attackers. Updating the plugin to a patched version is recommended.

Recommended defensive actions

  • Update the Masteriyo LMS plugin to a patched version (if available).
  • Restrict access to course announcements to authorized users only.
  • Monitor course announcements for any unauthorized modifications.
  • Implement additional security measures to prevent exploitation, such as Web Application Firewalls (WAFs).
  • Regularly review and update plugins to ensure they are up-to-date and patched.

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, including its description, CVSS score, and affected versions. The source item URL provides additional information on the vulnerability, including references to the vulnerable code.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-11773 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-11773

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-11773 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-11773

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.8/addons/course-announcement/Controllers/CourseAnnouncementController.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.8/addons/course-announcement/Controllers/CourseAnnouncementController.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.2.1/addons/course-announcement/Controllers/CourseAnnouncementController.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.2.1/addons/course-announcement/Controllers/CourseAnnouncementController.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.