Impact
The vulnerability is an instance of stored Cross‑Site Scripting (XSS) that occurs when the Masteriyo – LMS plugin fails to neutralize user‑supplied input during web page generation. As a result, malicious scripts can be injected, stored, and later executed in the context of any visitor to the affected WordPress site. The flaw is identified as CWE‑79. Only the behavior described in the CVE is known; no specific exploitation methods are disclosed.
Affected Systems
The Masteriyo – LMS learning‑management‑system plugin for WordPress is affected in all releases up to and including version 1.18.3. The vulnerability applies to any installation of the plugin from an unspecified starting version (n/a) through <= 1.18.3.
Risk and Exploitability
According to the CVSS score of 6.5, the vulnerability is rated moderate severity. The EPSS score of less than 1 % indicates a low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description of stored XSS, it is inferred that the vulnerability could be exploited by inserting malicious scripts into any input field that the plugin accepts, which are then rendered without further sanitization. However, the precise attack vector is not explicitly detailed in the CVE, so this inference requires confirmation.
OpenCVE Enrichment
EUVD