CVE-2026-82851: Unknown Masteriyo Lms
Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.
Affected products
- Unknown Masteriyo Lms: from 1.14.0, before 3.4.1 (fixed in 3.4.1)
Published 2026-09-12. Last modified 2026-09-14.