CVE-2026-10824
Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.
| Vendor | unknown |
| Product | masteriyo lms |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown masteriyo lms
Be the first to know when new medium vulnerabilities affecting unknown masteriyo lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Masteriyo LMS
0 < 2.2.1
References
Credits
Muni Nitish Kumar Yaddala WPScan