Impact
The Masteriyo LMS WordPress plugin before version 3.4.2 fails to verify that an authenticated request is being performed on the user’s own course‑progress records, allowing any logged‑in user to view another user’s learning activity. The ownership check is bypassed when a zero or missing identifier is supplied, causing the server to return the progress data for all learners on the site. Attacks require only credentials for a regular subscriber account and result in privacy violations with potential compliance implications.
Affected Systems
The affected product is the Masteriyo LMS WordPress plugin, all releases prior to 3.4.2. Users who have installed an earlier version of the plugin should be aware that they are vulnerable regardless of the site’s host or other plugins.
Risk and Exploitability
Because the vulnerability is limited to authenticated users, it is likely to be abused by any subscriber account with no additional privileges. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. However, the lack of an access control check in a widely installed plugin raises the risk for privacy exposure. The CVSS score is not provided in the public information, but the impact assessment indicates a moderate to high severity due to privacy breach.
OpenCVE Enrichment