Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.
Published: 2025-12-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Masteriyo - LMS WordPress plugin allows an attacker to retrieve embedded sensitive data that is not intended for public disclosure. The issue arises from improper handling or storage of system information, enabling access to data that may include configuration details or personal user data. The nature of the flaw aligns with CWE-497, indicating that sensitive data is retained in a readable form. The potential impact is a compromise of confidentiality, exposing information that could aid further attacks or lead to privacy violations.

Affected Systems

The flaw affects the Masteriyo - LMS learning‑management system plugin for WordPress, specifically all versions through 2.0.3 inclusive. Administrators should verify if their installation falls within this range and review the plugin version details in the WordPress admin dashboard.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is reported as less than 1%, suggesting a very low probability of exploitation in the wild at the time of this assessment. It is not listed in the CISA KEV catalog, meaning there is no publicly known, ongoing exploit. The likely attack vector involves a vulnerable WordPress site where an attacker can use the plugin’s exposed endpoint or administrative interface to request the sensitive data. No additional conditions such as authentication are explicitly documented in the description, so the exploit could be reachable to unauthenticated users if the endpoint is publicly accessible.

Generated by OpenCVE AI on April 29, 2026 at 12:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Masteriyo - LMS plugin to version 2.0.4 or later when the vendor releases a fix.
  • If an immediate update is not possible, remove or disable the plugin from the WordPress installation to eliminate the exposure.
  • Restrict access to any administrative interfaces that expose sensitive data, for example by applying IP whitelisting or using a firewall rule to block external access to the plugin’s endpoints.

Generated by OpenCVE AI on April 29, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress
Vendors & Products Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects Masteriyo - LMS: from n/a through <= 2.0.3.
Title WordPress Masteriyo - LMS plugin <= 2.0.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

Subscriptions

Masteriyo Masteriyo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:28:54.276Z

Reserved: 2025-10-29T03:08:27.751Z

Link: CVE-2025-64270

cve-icon Vulnrichment

Updated: 2025-12-18T20:22:33.790Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:13.483

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:15:09Z

Weaknesses