PatchSiren cyber security CVE debrief
CVE-2026-82846 Masteriyo CVE debrief
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. This vulnerability can have significant impacts on the security of WordPress installations with the Masteriyo LMS plugin. Defenders should assess exposure and prioritize verification of the plugin version and user role access controls.
- Vendor
- Masteriyo
- Product
- Masteriyo LMS WordPress plugin
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-05
- Original CVE updated
- 2026-09-06
- Advisory published
- 2026-09-05
- Advisory updated
- 2026-09-06
Who should care
Defenders responsible for WordPress installations with the Masteriyo LMS plugin should assess exposure and prioritize verification of the plugin version and user role access controls.
Why it matters
Defenders should prioritize verifying the version of the Masteriyo LMS WordPress plugin and ensuring that it is updated to 3.4.0 or later. Additionally, defenders should monitor for any suspicious activity related to course settings and user roles.
- Stored Cross-Site Scripting attacks can run in the session of anyone viewing the course, including a logged-in administrator
- Users with a course-author role can perform Stored Cross-Site Scripting attacks
Technical summary
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. The vulnerability is caused by inadequate sanitization and escaping of course settings, which can be exploited by users with a course-author role. This can lead to Stored Cross-Site Scripting attacks, which can have serious consequences, including unauthorized access and data breaches. Defenders should prioritize verifying the version of the Masteriyo LMS WordPress plugin and ensuring that it is updated to 3.4.0 or later. Additionally, defenders should monitor for any suspicious activity related to course settings and user roles. It is also essential to restrict access to course settings to authorized users only and implement compensating controls for exposed systems while remediation is scheduled and verified. Furthermore, defenders should review relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. To prevent similar vulnerabilities, it is crucial to follow secure coding practices and regularly update and patch software. By taking these steps, defenders can help protect their systems from potential attacks and minimize the risk of a security breach. The CVE record and NVD vulnerability detail page provide information about the vulnerability, including its description, CVSS score, and affected versions. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information. Therefore, defenders should exercise caution and consider multiple sources when assessing the vulnerability and developing a remediation plan. In addition to verifying the plugin version, defenders should also review the course settings and user roles to ensure that they are properly configured and secured. This includes monitoring for any suspicious activity related to course settings,
Defensive priority
Defenders should prioritize verifying the version of the Masteriyo LMS WordPress plugin and ensuring that it is updated to 3.4.0 or later. Additionally, defenders should monitor for any suspicious activity related to course settings and user roles.
Recommended defensive actions
- Verify the version of the Masteriyo LMS WordPress plugin and update to 3.4.0 or later
- Monitor for suspicious activity related to course settings and user roles
- Restrict access to course settings to authorized users only
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail page provide information about the vulnerability, including its description, CVSS score, and affected versions. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the provided information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82846 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82846
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82846 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82846
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/0ee2052c-90a8-4b98-947a-adc55feb1de7/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.