Impact
The Masteriyo LMS plugin for WordPress contains a missing capability check in the delete_item_permissions_check function of the CourseProgressItemsController. This flaw allows unauthenticated attackers to remove any course progress record belonging to any student, resulting in loss of learning progress data and the potential to tamper with assessment outcomes. The weakness is a missing authorization control (CWE‑862).
Affected Systems
All installations of Masteriyo LMS – LMS Course Builder, Quizzes & Certificates with versions 2.2.0 or earlier, including the 2.1.9 release referenced in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The attack requires no authentication or privileged access, meaning an attacker with internet access to the site can exploit the flaw trivially. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, so while the potential for widespread exploitation is not precisely measured, the lack of defensive checks makes the vulnerability actionable on any vulnerable instance.
OpenCVE Enrichment