Impact
The Masteriyo LMS WordPress plugin before version 3.4.1 fails to sanitize or escape a course field that is displayed in the course editor. A user with the instructor role can insert a script into that field, and the script is later rendered when higher‑privileged users such as administrators open the editor, resulting in stored cross‑site scripting. This allows the attacker to execute arbitrary JavaScript in the victim’s browser, potentially stealing session cookies, redirecting the user, or performing other malicious actions within the administrator context.
Affected Systems
All installations of the Masteriyo LMS WordPress plugin older than version 3.4.1 are affected. Users of WordPress sites that rely on this plugin for course management and need to update to the patched 3.4.1 release or later are advised to verify the vendor product and version.
Risk and Exploitability
The vulnerability can be exploited by any instructor who has permission to edit course content, which is common in many LMS deployments. Since the script is stored and executed automatically for any admin who later views or edits the same course, the impact is limited to browsers that load the editor page. The EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 6.8 denotes a medium severity. The vulnerability is not listed in the CISA KEV catalog. The attack vector and privileged target suggest a high potential risk if the site is accessible to many instructors, though the overall likelihood remains low.
OpenCVE Enrichment