CVE-2026-82848 PUBLISHED

Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure

Assigner: WPScan
Reserved: 31.08.2026 Published: 09.09.2026 Updated: 09.09.2026

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.

Product Status

Vendor Unknown
Product Masteriyo LMS
Versions Default: unaffected
  • affected from 1.3.1 to 3.4.0 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE