CVE-2026-82848: Unknown Masteriyo Lms

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.

Affected products

  • Unknown Masteriyo Lms: from 1.3.1, before 3.4.0 (fixed in 3.4.0)

Published 2026-09-09. Last modified 2026-09-09.