CVE-2026-62132
A CVE record for a Subscriber Broken Access Control vulnerability in Masteriyo - LMS version 3.4.0 and earlier was published on September 11, 2026. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A CVE record for a Subscriber Broken Access Control vulnerability in Masteriyo - LMS version 3.4.0 and earlier was published on September 11, 2026. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.
Unauthenticated PHP Object Injection vulnerability in Masteriyo - LMS plugin versions up to 3.4.0. The CVE record was published on 2026-09-11T19:17:43.583Z and has not been modified since then.
The Masteriyo LMS plugin for WordPress has a vulnerability allowing unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController. This affects all versions up to and including 2.2.0, enabling unauthenticated attackers to delete arbitrary course progress records belonging to any student.
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator. This vulnerability can have significant impacts on the security of Word [truncated]
The Masteriyo LMS WordPress plugin before 2.3.1 has a vulnerability that allows unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators. This is due to an unauthenticated AJAX action used to clear user sessions that does not correctly verify authorization. The vulnerability has a high impact on the confidentiality and integrity of the aff [truncated]
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This vulnerability allows authenticated attackers, with student-level access and above, to modify the description of arbitrary course announcements authored by instructors or administrators. The plugin fails to properly verify that a user is [truncated]
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key due to insufficient webhook signature verification. This vulnerability allows unauthenticated attackers to send fake Stripe webhook events, potentially leading to unauthorized access to paid course content. Users of Masteriyo LMS should verify thei [truncated]