masteriyo Vulnerabilities and Affected Products
Vulnerabilities associated with Masteriyo LMS – LMS Course Builder, Quizzes & Certificates.
Products
Clear product- Masteriyo - LMS9 vulnerabilities
- masteriyo4 vulnerabilities
- Masteriyo LMS – Online Course Builder for eLearning, LMS & Education4 vulnerabilities
- Masteriyo LMS2 vulnerabilities
- Masteriyo LMS – LMS Course Builder, Quizzes & Certificates1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-11773MEDIUM | Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement ModificationThe Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with student-level access and above, to modify the description (post content) of arbitrary course announcements authored by instructors or administrators. CWE-862Jun 27, 2026 | CVSS4.3v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |