Masteriyo Lms

WordPress plugin · masteriyo-lms · WordPress.org ↗
2
Critical
0
High
8
Known total
0
Unfixed
Running Masteriyo Lms on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
CRITICAL
CVSS 9.9
Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
CVE.org
>=0, <3.4.1 v3.4.1 CVE-2026-82845 Sep 12, 2026
CRITICAL
CVSS 9.1
Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)
CVE.org
>=0, <2.3.1 v2.3.1 CVE-2026-13332 Jul 27, 2026
MEDIUM
CVSS 6.8
Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
CVE.org
>=0, <3.4.1 v3.4.1 CVE-2026-82847 Sep 12, 2026
MEDIUM
CVSS 5.3
Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure
CVE.org
>=1.3.1, <3.4.0 v3.4.0 CVE-2026-82848 Sep 9, 2026
MEDIUM
CVSS 6.8
Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields
CVE.org
>=1.18.0, <3.4.0 v3.4.0 CVE-2026-82846 Sep 5, 2026
MEDIUM
CVSS 6.1
Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description
CVE.org
>=0, <2.3.3 v2.3.3 CVE-2026-19712 Aug 16, 2026
MEDIUM
CVSS 6.5
Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion
CVE.org
>=0, <2.2.1 v2.2.1 CVE-2026-10824 Jun 25, 2026
LOW
CVSS 2.7
Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR
CVE.org
>=1.14.0, <3.4.1 v3.4.1 CVE-2026-82851 Sep 12, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.