masteriyo Vulnerabilities and Affected Products
Vulnerabilities associated with masteriyo.
Products
Clear product- Masteriyo - LMS9 vulnerabilities
- masteriyo4 vulnerabilities
- Masteriyo LMS – Online Course Builder for eLearning, LMS & Education4 vulnerabilities
- Masteriyo LMS2 vulnerabilities
- Masteriyo LMS – LMS Course Builder, Quizzes & Certificates1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43158HIGH | WordPress Masteriyo LMS plugin <= 1.11.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4. CWE-862Nov 1, 2024 | CVSS7.5v3.1 | EPSS0.522% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43159MEDIUM | WordPress Masteriyo LMS plugin <= 1.11.6 - Broken Access Control vulnerabilityMissing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6. CWE-862Nov 1, 2024 | CVSS5.3v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-10008HIGH | Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege EscalationThe Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authenticated attackers, with student-level access and above, to modify the roles of arbitrary users. As a result, attackers can escalate their privileges to the Administrator and demote … CWE-862Oct 29, 2024 | CVSS8.8v3.1 | EPSS0.631% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-24882CRITICAL | WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilityIncorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2. | CVSS9.8v3.1 | EPSS2.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |