Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

masteriyo — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting masteriyo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Masteriyo is a WordPress LMS plugin enabling online course creation and management. Historically, it has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper access controls. The plugin has accumulated 11 CVEs to date, with several critical vulnerabilities allowing unauthenticated attackers to execute arbitrary code or compromise user accounts. Security researchers have identified consistent patterns in its vulnerability profile, particularly in areas handling user-generated content and authentication mechanisms. No major public security incidents have been widely reported, though the high number of CVEs indicates a history of security challenges requiring ongoing vigilance.

Found 4 results / 18 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-5167 Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint — Masteriyo LMS – Online Course Builder for eLearning, LMS & Education CWE-639 5.3 Medium 2026-04-08
CVE-2026-4484 Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator — Masteriyo LMS – Online Course Builder for eLearning, LMS & Education CWE-862 8.8 High 2026-03-26
CVE-2024-10000 Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Stored Cross-Site Scripting via Ask a Question Functionality — Masteriyo LMS – Online Course Builder for eLearning, LMS & Education CWE-79 6.4 Medium 2024-10-29
CVE-2024-10008 Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation — Masteriyo LMS – Online Course Builder for eLearning, LMS & Education CWE-862 8.8 High 2024-10-29

This page lists every published CVE security advisory associated with masteriyo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.