Extension WordPress
Vulnérabilités Masteriyo LMS – LMS Course Builder, Quizzes & Certificates
Cette page rassemble les failles publiées pour Masteriyo LMS – LMS Course Builder, Quizzes & Certificates, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Masteriyo LMS – LMS Course Builder, Quizzes & Certificates
16 fiches
Masteriyo LMS <= 2.2.1 – Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user…
*-2.2.1
2.3.0
26/06/2026
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.2.0 – Authenticated (Subscriber+) Privilege Escalation
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above,…
*-2.2.0
2.2.1
08/06/2026
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates <= 2.1.8 – Missing Authorization
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.8. This makes it…
*-2.1.8
2.1.9
28/05/2026
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 – Missing Authorization
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.1.5. This…
*-2.1.5
2.1.6
08/04/2026
Masteriyo LMS <= 2.1.7 – Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in versions up to and including 2.1.7. This is due to insufficient webhook signature verification…
*-2.1.7
2.1.8
07/04/2026
Masteriyo LMS <= 2.1.6 – Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This…
*-2.1.6
2.1.7
25/03/2026
Masteriyo – LMS <= 2.0.3 – Authenticated (Subscriber+) Sensitive Information Exposure
The Masteriyo LMS – Online Course Builder for eLearning, LMS & Education plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with Subscriber-level…
*-2.0.3
2.0.4
30/11/2025
Masteriyo – LMS <= 1.18.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Masteriyo – LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-1.18.3
1.18.4
30/07/2025
Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 – Authenticated (Student+) Stored Cross-Site Scripting via Ask a Question Functionality
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization…
*-1.13.3
1.13.4
28/10/2024
Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 – Authenticated (Student+) Missing Authorization to Privilege Escalation
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and…
*-1.13.3
1.13.4
28/10/2024
Masteriyo – LMS <= 1.11.4 – Authenticated (Student+) Insecure Direct Object Reference
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.11.4 due to missing validation on the 'course_id' user controlled…
*-1.11.4
1.11.5
12/08/2024
Masteriyo – LMS <= 1.11.4 – Missing Authorization
The Masteriyo – LMS plugin for WordPress is vulnerable to unauthorized access of dat due to a missing capability check on several REST API endpoints in versions up to, and including, 1.11.4. This makes it possible for unauthenticated…
*-1.11.4
1.11.5
07/08/2024
Masteriyo – LMS <= 1.11.6 – Missing Authorization
The Masteriyo – LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item() function in versions up to, and including, 1.11.6. This makes it possible for unauthenticated attackers…
*-1.11.6
1.12.0
07/08/2024
Masteriyo – LMS <= 1.7.3 – Insecure Direct Object Reference
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.3 via the REST API due to missing validation on…
*-1.7.3
1.7.4
30/04/2024
Masteriyo – LMS <= 1.7.2 – Unauthenticated Privilege Escalation
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_logged_in_user() function in all versions up to, and including, 1.7.2. This…
*-1.7.2
1.7.3
05/04/2024
Masteriyo – LMS for WordPress <= 1.6.7 – Sensitive Information Exposure
The Masteriyo – LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.7 via the 'get_item' REST callback. This can allow authenticated attackers to extract sensitive data including user metadata.
[*, 1.6.8)
1.6.8
03/07/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.