Unknown Masteriyo LMS

7 known vulnerabilities in Unknown Masteriyo LMS, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-82850 CVSS 4.3 medium The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a…
  • CVE-2026-82849 CVSS 4.3 medium The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being…
  • CVE-2026-82851 CVSS 2.7 low The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for…
  • CVE-2026-82847 CVSS 6.8 medium The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the…
  • CVE-2026-82845 CVSS 9.9 critical The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they…
  • CVE-2026-82848 CVSS 5.3 medium The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over…
  • CVE-2026-82846 CVSS 6.8 medium The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page…