Known Vulnerabilities for Masteriyo by Masteriyo
Listed below are 4 of the newest known vulnerabilities associated with "Masteriyo" by "Masteriyo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82851 json | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user re... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-82848 json | The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-82847 json | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it b... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-82846 json | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in ... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-82845 json | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserializ... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-73996 json | Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-65463 json | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-62132 json | Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-62107 json | Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-59513 json | Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | Not Provided | 2026-07-23 | 2026-07-23 |