Unknown Masteriyo LMS
7 known vulnerabilities in Unknown Masteriyo LMS, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82850 CVSS 4.3 medium The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a…
- CVE-2026-82849 CVSS 4.3 medium The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being…
- CVE-2026-82851 CVSS 2.7 low The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for…
- CVE-2026-82847 CVSS 6.8 medium The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the…
- CVE-2026-82845 CVSS 9.9 critical The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they…
- CVE-2026-82848 CVSS 5.3 medium The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over…
- CVE-2026-82846 CVSS 6.8 medium The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page…