Impact
The Masteriyo LMS4.1 fails to sanitize or escape a course field that is displayed in the course editor. A user with the instructor role can insert a script into that field, and the script is later rendered when higher‑privileged in stored cross‑site scripting. This allows the attacker to execute arbitrary JavaScript in the victim’s browser, potentially stealing session cookies, redirecting the user, or performing other malicious actions within the administrator context.
Affected Systems
All installations of the Masteriyo LMS WordPress plugin older than version 3.4.1 are affected. Users of WordPress sites that rely on this plugin for course management and need to update to the patched 3.4.1 release or later are advised to verify the vendor product and version.
Risk and Exploitability
The vulnerability can be edit course content, which is common in many LMS deployments. Since the script is stored and executed automatically for any admin who later views or edits the same course, the impact is limited EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 6.8 denotes a medium severity. The vulnerability is not listed in the CISA KEV catalog. The attack vector and privileged target suggest a high potential risk if the site is accessible to many instructors, though the overall likelihood remains low.
OpenCVE Enrichment