Description
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation.

This issue affects Masteriyo - LMS: from n/a through 2.2.0.
Published: 2026-06-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper privilege assignment within the Masteriyo – LMS plugin, enabling users with lower or default access to elevate their privileges. The flaw is classified as a Privilege Management Error (CWE‑266). An attacker who can interact with the plugin’s administrative interface could potentially gain administrator‑level rights, leading to full control over the WordPress site, including data theft, modification, or site takeover. The official description confirms that the flaw permits privilege escalation.

Affected Systems

The affected product is the WordPress Masteriyo – LMS plugin developed by ThemeGrill. All released plugin versions up to version 2.2.0 are impacted; the vulnerability list states the issue applies from n/a through 2.2.0. Any WordPress site running an affected Masteriyo installation must be assessed, especially those that expose the administrative area or allow user role management.

Risk and Exploitability

The CVSS score of 8.8 signifies a high severity risk, and the EPSS score of 0.00245 indicates a very low probability of exploitation. The lack of a KEV listing suggests there have not been widespread public exploits yet. The likely attack vector is from an authenticated user with limited access who leverages the plugin’s privilege assignment flaw to gain elevated rights. Once the vulnerability is exploited, an attacker can achieve complete administrative control over the WordPress site, potentially leading to data compromise, site defacement, or further lateral movement within the hosting environment.

Generated by OpenCVE AI on June 17, 2026 at 02:36 UTC.

Remediation

Vendor Solution

Update the WordPress Masteriyo - LMS Plugin to the latest available version (at least 2.2.1).


OpenCVE Recommended Actions

  • Apply the latest update of the Masteriyo – LMS Plugin (version 2.2.1 or newer) to all WordPress sites that use the plugin.
  • Remove or delete any residual files from older Masteriyo installations to eliminate legacy code that may still be exploitable.
  • Review role assignments for all site users and revoke any super‑user or administrator privileges that are no longer required, ensuring the principle of least privilege.

Generated by OpenCVE AI on June 17, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 15 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.
Title WordPress Masteriyo - LMS plugin <= 2.2.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-15T15:51:36.374Z

Reserved: 2026-05-27T15:12:19.105Z

Link: CVE-2026-49111

cve-icon Vulnrichment

Updated: 2026-06-15T15:51:31.990Z

cve-icon NVD

Status : Deferred

Published: 2026-06-15T14:16:35.973

Modified: 2026-06-15T20:42:32.707

Link: CVE-2026-49111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T02:45:02Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment