Impact
The vulnerability is a stored cross‑site scripting flaw in the Masteriyo LMS WordPress plugin. Course settings are output unsanitized, enabling a course‑author with write access to inject arbitrary script that runs in the context of anyone who views the affected course page, including logged‑in administrators. The attacker can execute client‑side code, steal session cookies, redirect users, or perform phishing attacks. This weakness is cataloged as CWE‑79.
Affected Systems
This flaw affects installations of the Masteriyo LMS plugin for WordPress with versions before 3.4.0. Any site that uses the default course‑author role and the custom fields feature is vulnerable. The issue is not limited to a specific WordPress core version or plugin bundle, but applies to all affected Masteriyo LMS versions described.
Risk and Exploitability
No CVSS score is provided in the public advisory and the EPSS score is unavailable, indicating that the exact likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers need course‑author privileges to inject malicious payloads, so the threat is limited to users who already have legitimate editing rights on the LMS. However, because the malicious code runs in the browser session of any visitor, including administrators, the impact can be high if a privileged user views a compromised page before the vulnerability is patched.
OpenCVE Enrichment