CVE-2026-82847 PUBLISHED

Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights

Assigner: WPScan
Reserved: 31.08.2026 Published: 12.09.2026 Updated: 12.09.2026

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.

Product Status

Vendor Unknown
Product Masteriyo LMS
Versions Default: unaffected
  • affected from 0 to 3.4.1 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE