Description
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to LMS Data
Action: Update
AI Analysis

Impact

The Masteriyo – LMS WordPress plugin versions up to and including 3.4.0 contain a broken access" role to perform privileged actions. This weakness, identified as CWE‑862, permits unauthorized access to course content, user data, or administrative functions that should be restricted. The exploit can lead to confidentiality and integrity violations within the LMS, potentially exposing sensitive student information.

Affected Systems

Affected product: Masteriyo – 3.4.0 or older are impacted. The vulnerability applies to any WordPress site that has the plugin activated and is configured with the default access roles. No other vendors or product versions are implicitly affected.

Risk and Exploitability

The CVSS score for this vulnerability is 5.3, indicating moderate severity. The EPSS score is < 1 %, suggesting an extremely low likelihood of exploitation and indicating that it is not listed in the CISA KEV catalog. The likely attack vector is administrative privilege escalation via authenticated subscriber accounts: an attacker within the subscriber role can request endpoints that perform privileged operations. Because the flaw is not publicly disclosed or accompanied by a widely available exploit, the immediate risk depends on the number of users granted subscriber privileges and the sensitivity of the LMS data.

Generated by OpenCVE AI on September 21, 2026 at 03:29 UTC.

Remediation

Vendor Solution

Update the WordPress Masteriyo - LMS Plugin to the latest available version (at least 3.4.1).


OpenCVE Recommended Actions

  • Update the Masteriyo – LMS plugin to at least version 3.4.1 to fix the broken access control flaw.
  • Verify that role‑based access checks are properly enforced by testing or administrative pages without elevated permissions.
  • If the plugin is no longer required, deactivate or uninstall it to eliminate the attack surface; otherwise, review and harden the site's role configurations to ensure subscribers have only the minimum needed capabilities.

Generated by OpenCVE AI on September 21, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress
Vendors & Products Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
Title WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Masteriyo Masteriyo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-11T20:19:11.115Z

Reserved: 2026-07-13T06:15:19.260Z

Link: CVE-2026-62132

cve-icon Vulnrichment

Updated: 2026-09-11T20:12:58.965Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:44.493

Modified: 2026-09-11T21:17:12.583

Link: CVE-2026-62132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:30:08Z

Weaknesses