Description
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross Site Scripting (XSS) flaw that allows a subscriber to inject malicious scripts into pages rendered by the Masteriyo – LMS plugin. This flaw can lead to the execution of arbitrary JavaScript in the context of an affected user, potentially enabling session hijacking, credential theft, or defacement. The weakness is reflected by the CWE‑79 classification. The impact is limited to the user who visits the injected content, but an attacker could potentially spread the payload through front‑end components used by many users.

Affected Systems

The issue affects WordPress installations that use the Masteriyo – LMS plugin version 2.3.0 or earlier. The plugin is provided by the vendor Masteriyo through the Masteriyo – LMS product line. No other vendors or product forks are listed in the CNA data.

Risk and Exploitability

The CVSS score of 6.5 indicates substantial severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a user‑generated input field within the plugin that is not properly sanitized, enabling an attacker to embed JavaScript. Without additional mitigations the vulnerability could be leveraged whenever a user navigates to the affected page rendering the input.

Generated by OpenCVE AI on August 3, 2026 at 22:22 UTC.

Remediation

Vendor Solution

Update the WordPress Masteriyo - LMS Plugin to the latest available version (at least 2.3.1).


OpenCVE Recommended Actions

  • Upgrade the WordPress Masteriyo – LMS plugin to version 2.3.1 or later.
  • Delete any remaining legacy plugin files or directories from earlier versions to ensure no old code remains.
  • Flush all caching mechanisms, including the WordPress cache, CDN cache, and any object caching plugins.

Generated by OpenCVE AI on August 3, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress
Vendors & Products Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
Title WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Masteriyo Masteriyo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:44:09.148Z

Reserved: 2026-07-05T21:27:29.080Z

Link: CVE-2026-59513

cve-icon Vulnrichment

Updated: 2026-07-23T13:44:03.649Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:31.983

Modified: 2026-07-23T14:17:28.120

Link: CVE-2026-59513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')