PatchSiren

Masteriyo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Masteriyo CVE published 2026-07-27

CVE-2026-13332

The Masteriyo LMS WordPress plugin before 2.3.1 has a vulnerability that allows unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators. This is due to an unauthenticated AJAX action used to clear user sessions that does not correctly verify authorization. The vulnerability has a high impact on the confidentiality and integrity of the aff [truncated]

MEDIUM masteriyo CVE published 2026-06-27

CVE-2026-11773

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This vulnerability allows authenticated attackers, with student-level access and above, to modify the description of arbitrary course announcements authored by instructors or administrators. The plugin fails to properly verify that a user is [truncated]

MEDIUM masteriyo CVE published 2026-04-08

CVE-2026-5167

The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key due to insufficient webhook signature verification. This vulnerability allows unauthenticated attackers to send fake Stripe webhook events, potentially leading to unauthorized access to paid course content. Users of Masteriyo LMS should verify thei [truncated]