CVE-2026-82847
Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
| Vendor | unknown |
| Product | masteriyo lms |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown masteriyo lms
Be the first to know when new medium vulnerabilities affecting unknown masteriyo lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Masteriyo LMS
0 < 3.4.1
References
Credits
Karthik Ramakrishnan WPScan