CVE-2026-13332
CRITICALMasteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)
Title source: cnaDescription
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/f987c823-f215-48f6-86fe-8d898f2c2d94/
Scores
CVSS v3
9.1
EPSS
0.0024
EPSS Percentile
15.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (1)
None/Masteriyo LMS
< 2.3.1
Published
Jul 27, 2026
Tracked Since
Jul 27, 2026