Impact
The Masteriyo LMS WordPress plugin fails to check user authorization before serving enrollment records via its REST API. An unauthenticated user can request any enrollment record by iterating sequential identifiers, revealing a learner’s enrollment status, timestamps and course‑progress data. Enrolled users can also view other learners’ records, exposing sensitive educational information that should remain private.
Affected Systems
All installations of Masteriyo LMS prior to version 3.4.0 – specifically versions 1.3.1 through 2.3.3 – are susceptible, regardless of the WordPress site configuration. The vulnerability exists in every deployment of the plugin that has the affected REST endpoints enabled.
Risk and Exploitability
The CVSS score of 5.3 marks this flaw as moderate severity but the lack of authentication or authorization checks makes exploitation trivial for anyone able to reach the REST API. EPSS is reported as less than 1%, indicating a low but nonzero likelihood of real‑world exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting no confirmed public exploits yet. Nonetheless, the ability for anyone to access learner data poses a significant confidentiality risk that should be addressed immediately.
OpenCVE Enrichment