CVE-2026-82849
Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.
| Vendor | unknown |
| Product | masteriyo lms |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown masteriyo lms
Be the first to know when new unknown vulnerabilities affecting unknown masteriyo lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Masteriyo LMS
0 < 3.4.2
References
Credits
Karthik Ramakrishnan WPScan