Description
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The Masteriyo LMS WordPress plugin fails to check user authorization before serving enrollment records via its REST API. An unauthenticated user can request any enrollment record by iterating sequential identifiers, revealing a learner’s enrollment status, timestamps and course‑progress data. Enrolled users can also view other learners’ records, exposing sensitive educational information that should remain private.

Affected Systems

All installations of Masteriyo LMS prior to version 3.4.0 – specifically versions 1.3.1 through 2.3.3 – are susceptible, regardless of the WordPress site configuration. The vulnerability exists in every deployment of the plugin that has the affected REST endpoints enabled.

Risk and Exploitability

The CVSS score of 5.3 marks this flaw as moderate severity but the lack of authentication or authorization checks makes exploitation trivial for anyone able to reach the REST API. EPSS is reported as less than 1%, indicating a low but nonzero likelihood of real‑world exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting no confirmed public exploits yet. Nonetheless, the ability for anyone to access learner data poses a significant confidentiality risk that should be addressed immediately.

Generated by OpenCVE AI on September 9, 2026 at 20:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Masteriyo LMS plugin to version 3.4.0 or later, which adds the necessary authorization checks to the enrollment endpoints.
  • If an immediate upgrade is not possible, block unauthenticated HTTP requests to the affected REST API URLs using .htaccess rules, a web application firewall rule, or a WordPress REST API authentication plug‑in so that only logged‑in users can reach the enrollment routes.
  • Configure the plugin or your application to require authentication for all Masteriyo LMS REST API calls, ensuring that enrollment data is only returned after valid user credentials and role checks have been performed.

Generated by OpenCVE AI on September 9, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.
Title Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-09T15:37:54.624Z

Reserved: 2026-08-31T08:27:27.917Z

Link: CVE-2026-82848

cve-icon Vulnrichment

Updated: 2026-09-09T15:32:23.527Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:17.453

Modified: 2026-09-09T16:17:11.777

Link: CVE-2026-82848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T21:00:12Z

Weaknesses