CVE-2026-82847
Received Received - Intake

Stored Cross-Site Scripting in Masteriyo LMS WordPress Plugin

Vulnerability report for CVE-2026-82847, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masteriyo lms to 3.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Masteriyo LMS WordPress plugin before version 3.4.1. It occurs because the plugin does not properly sanitize and escape a course field before displaying it in the course editor. This allows users with the instructor role to inject malicious scripts that target higher-privileged users like administrators.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the Masteriyo LMS plugin version prior to 3.4.1. Log in as an instructor and inspect course fields in the editor for unusual or malicious scripts. Review browser console logs for any unexpected script executions when editing courses.

Impact Analysis

If exploited, this vulnerability could allow an attacker with the instructor role to inject malicious scripts into the course editor. These scripts could then be executed by higher-privileged users such as administrators, potentially leading to unauthorized actions, data theft, or further compromise of the WordPress site.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing sensitive user data or administrative actions. If exploited, it may lead to unauthorized access or data breaches, violating privacy and security requirements under these regulations.

Mitigation Strategies

Immediately update the Masteriyo LMS plugin to version 3.4.1 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review user roles and permissions to ensure instructors do not have unnecessary privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82847. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart