Impact
The Masteriyo LMS plugin allows any authenticated user, such as a student, to retrieve correct quiz answers for all quizzes on the site, including those in courses the user is not enrolled in. The redaction logic applies only to a limited set of question types, so answers for all other types are exposed in full. This oversight results in the unauthorized disclosure of assessment content, compromising the privacy of quiz material and undermining the integrity of course grading. The core weakness is improper access control, enabling data exposure to users who should be denied that information.
Affected Systems
Masteriyo LMS WordPress plugin versions earlier than 3.4.2 are affected. The vendor is Masteriyo LMS; no more granular affected‑version data is provided in the CVE record.
Risk and Exploitability
Because any authenticated user can invoke the exposed endpoint, exploitation requires only a valid account. No public exploits are reported, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential impact is high due to the sensitive nature of quiz answers. The attack vector is essentially in‑application; an attacker could trigger the action from the user interface or via automated requests with a valid authentication cookie.
OpenCVE Enrichment