Impact
The Masteriyo LMS WordPress plugin contains an IDOR flaw that allows any user with the instructor role to download the full content and metadata of any post, regardless of ownership. This flaw is present in all releases from version 1.14.0 through 3.4.0, and includes access to private and draft courses belonging to other instructors. The result is a clear confidentiality breach: unauthorized instructors can view, replicate, or redistribute unpublished course material, constituting a loss of intellectual property and a breach of trust within the platform.
Affected Systems
The vulnerability affects the Masteriyo LMS WordPress plugin. Versions 1.14.0 through 3.4.0 are impacted. Site administrators running any of these releases should verify whether the instructor role has unrestricted download access and consider whether additional controls are needed.
Risk and Exploitability
The vulnerability requires authenticated access to the WordPress site with the instructor role; no additional network privileges are necessary. The CVSS score of 2.7 indicates a low severity impact, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The flaw is not listed in the CISA KEV attack vector is the plugin’s download endpoint, where ownership checks are omitted.
OpenCVE Enrichment