CVE-2026-19712
Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators. This affects default single-site installations. Sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there.
| Vendor | unknown |
| Product | masteriyo lms |
| Published | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown masteriyo lms
Be the first to know when new unknown vulnerabilities affecting unknown masteriyo lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Masteriyo LMS
0 < 2.3.3
References
Credits
Farid Narimanov WPScan