Impact
The Masteriyo – LMS WordPress plugin versions up to and including 3.4.0 contain a broken access" role to perform privileged actions. This weakness, identified as CWE‑862, permits unauthorized access to course content, user data, or administrative functions that should be restricted. The exploit can lead to confidentiality and integrity violations within the LMS, potentially exposing sensitive student information.
Affected Systems
Affected product: Masteriyo – 3.4.0 or older are impacted. The vulnerability applies to any WordPress site that has the plugin activated and is configured with the default access roles. No other vendors or product versions are implicitly affected.
Risk and Exploitability
The CVSS score for this vulnerability is 5.3, indicating moderate severity. The EPSS score is < 1 %, suggesting an extremely low likelihood of exploitation and indicating that it is not listed in the CISA KEV catalog. The likely attack vector is administrative privilege escalation via authenticated subscriber accounts: an attacker within the subscriber role can request endpoints that perform privileged operations. Because the flaw is not publicly disclosed or accompanied by a widely available exploit, the immediate risk depends on the number of users granted subscriber privileges and the sensitivity of the LMS data.
OpenCVE Enrichment