Showing 1 vulnerability on this page for Masteriyo LMS – LMS Course Builder, Quizzes & Certificates

Signals CISA KEV Ransomware Nuclei
masteriyo vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with student-level access and above, to modify the description (post content) of arbitrary course announcements authored by instructors or administrators.

CWE-862Jun 27, 2026
CVSS4.3v3.1EPSS0.149%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX