在 Masteriyo LMS WordPress 插件 3.4.2 版本之前,插件未对测验答案密钥的访问进行限制,导致任何经过身份验证的用户(例如学生)都可以获取站点上任意测验的正确答案,包括其未注册的课程中的测验。由于仅对固定类型的问题应用了隐藏答案的脱敏措施,因此对于其他所有类型的问题,只要用户能够查看问题,其完整答案就会被返回给任何可访问该问题的用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Masteriyo LMS | 0 ~ 3.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93662 | Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via ' | |
| CVE-2026-93661 | Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR | |
| CVE-2026-88847 | MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation | |
| CVE-2026-89004 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosu | |
| CVE-2026-89005 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category | |
| CVE-2026-89002 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview | |
| CVE-2026-88843 | MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widg | |
| CVE-2026-88846 | MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disa | |
| CVE-2026-88845 | MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import | |
| CVE-2026-82195 | 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion | |
| CVE-2026-82849 | Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR | |
| CVE-2026-84151 | The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-L | |
| CVE-2026-74991 | WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellati | |
| CVE-2026-80338 | CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler | |
| CVE-2026-80513 | wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields |
No comments yet