masteriyo Vulnerabilities and Affected Products
Vulnerabilities associated with Masteriyo - LMS.
Products
Clear product- Masteriyo - LMS9 vulnerabilities
- masteriyo4 vulnerabilities
- Masteriyo LMS – Online Course Builder for eLearning, LMS & Education4 vulnerabilities
- Masteriyo LMS2 vulnerabilities
- Masteriyo LMS – LMS Course Builder, Quizzes & Certificates1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-65463MEDIUM | WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerabilitySubscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. CWE-639Jul 23, 2026 | CVSS5.4v3.1 | EPSS0.287% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59513MEDIUM | WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerabilitySubscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. CWE-79Jul 23, 2026 | CVSS6.5v3.1 | EPSS0.211% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64270MEDIUM | WordPress Masteriyo - LMS plugin <= 2.0.3 - Sensitive Data Exposure vulnerabilityExposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3. CWE-497Dec 18, 2025 | CVSS6.5v3.1 | EPSS0.287% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-54699MEDIUM | WordPress Masteriyo - LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) VulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3. CWE-79Aug 14, 2025 | CVSS6.5v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33939MEDIUM | WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerabilityAuthentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.3. | CVSS5.3v3.1 | EPSS0.895% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-43158HIGH | WordPress Masteriyo LMS plugin <= 1.11.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. CWE-862Nov 1, 2024 | CVSS7.5v3.1 | EPSS0.522% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43159MEDIUM | WordPress Masteriyo LMS plugin <= 1.11.6 - Broken Access Control vulnerabilityMissing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6. CWE-862Nov 1, 2024 | CVSS5.3v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43239MEDIUM | WordPress Masteriyo LMS plugin <= 1.11.4 - Insecure Direct Object Reference (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. CWE-639Aug 18, 2024 | CVSS4.3v3.1 | EPSS0.292% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-24882CRITICAL | WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilityIncorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2. | CVSS9.8v3.1 | EPSS2.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |