Impact
The Masteriyo LMS WordPress plugin before version 2.3.1 allows an attacker to call an AJAX action that clears user sessions without validating proper authorization. An attacker can therefore terminate the active session of any user, including administrators, effectively denying those users access to the site. This flaw, classified as CWE-287 (Improper Authentication), can disrupt normal site operation and create a DoS scenario for legitimate users.
Affected Systems
WordPress sites using the Masteriyo LMS plugin older than the 2.3.1 release are vulnerable. Specific vendor and product names are not further enumerated beyond the generic Masteriyo LMS designation, and version information is limited to "< 2.3.1".
Risk and Exploitability
The vulnerability is assigned a CVSS score of 9.1, indicating critical severity. The EPSS score is 0.0024 (less than 1%), and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and requires no authentication; an unauthenticated attacker could issue the vulnerable AJAX request from any network to force-logout any user. Because the flaw permits the action without credentials and without access control checks, exploitation is straightforward once the endpoint is discovered.
OpenCVE Enrichment