Impact
The Masteriyo LMS WordPress plugin before 2.3.3 fails to sanitise and escape content in the quiz description field. Instructors, which have the permission to store unfiltered HTML, can insert malicious scripts that are then rendered for every visitor of the affected page. This Stored Cross‑Site Scripting allows attackers to execute arbitrary JavaScript in the context of any user, leading to potential session hijacking, credential theft, defacement or further malicious activity when visitors—including administrators—view quiz pages.
Affected Systems
The vulnerability impacts the Masteriyo LMS plugin version 2.3.2 and earlier when deployed on default single‑site WordPress installations. Sites running multisite, or those that have defined DISALLOW_UNFILTERED_HTML, are not affected because the instructor capability to store unfiltered HTML is not granted in those environments.
Risk and Exploitability
The vulnerability has no publicly reported exploit probability metric and is not listed in the CISA KEV catalog. It is exploitable only if an attacker can create or modify a quiz as an instructor, or compromises an instructor account. The stored nature of the attack means that once a malicious script is embedded, it can affect any visitor without further action. The lack of a public EPSS score suggests a lower exploitation likelihood, but the high impact of XSS warrants caution. The attack vector is via content stored in quiz descriptions accessible to instructors, and the impact extends to all users visiting the affected page.
OpenCVE Enrichment