CVE-2026-82849
Received Received - Intake

Authentication Bypass in Masteriyo LMS Plugin

Vulnerability report for CVE-2026-82849, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: WPScan

Description

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masteriyo lms to 3.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Insecure Direct Object Reference (IDOR) vulnerability in the Masteriyo LMS WordPress plugin before version 3.4.2. It allows any authenticated user, including self-registered subscribers, to access and view another user's course progress without proper authorization. The plugin fails to verify ownership of course-progress records, and when no specific account is requested, it returns all learner records on the site.

Detection Guidance

To detect this vulnerability, check if your Masteriyo LMS plugin version is below 3.4.2. You can verify the installed version via WordPress admin panel or by inspecting the plugin files. No specific commands are provided in the context, but monitoring for unauthorized access to course-progress records may indicate exploitation.

Impact Analysis

An attacker could exploit this to view sensitive learning activity data of other users, including their progress, courses taken, and potentially personal information. This could lead to privacy breaches, data leaks, or misuse of user data. The impact is higher if the site has many users or sensitive course content.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR by exposing personal data without consent. It may also breach HIPAA if the plugin handles protected health information. Organizations using this plugin must ensure user data is protected to maintain compliance.

Mitigation Strategies

Immediately update the Masteriyo LMS plugin to version 3.4.2 or later. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Review user access logs for suspicious activity related to course-progress data access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82849. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart