Impact
The vulnerability is a Cross Site Scripting (XSS) flaw that allows a subscriber to inject malicious scripts into pages rendered by the Masteriyo – LMS plugin. This flaw can lead to the execution of arbitrary JavaScript in the context of an affected user, potentially enabling session hijacking, credential theft, or defacement. The weakness is reflected by the CWE‑79 classification. The impact is limited to the user who visits the injected content, but an attacker could potentially spread the payload through front‑end components used by many users.
Affected Systems
The issue affects WordPress installations that use the Masteriyo – LMS plugin version 2.3.0 or earlier. The plugin is provided by the vendor Masteriyo through the Masteriyo – LMS product line. No other vendors or product forks are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.5 indicates substantial severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a user‑generated input field within the plugin that is not properly sanitized, enabling an attacker to embed JavaScript. Without additional mitigations the vulnerability could be leveraged whenever a user navigates to the affected page rendering the input.
OpenCVE Enrichment