MEDIUM
CVE-2026-10824
CVSS
6.5
Description
The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.
Summary dbcve.org
The Masteriyo LMS WordPress plugin before version 2.2.1 has a broken access control vulnerability in its course-progress REST API controller. The endpoint lacks authorization checks, enabling any unauthenticated user to read and permanently delete any user's course-progress records via direct object reference.
Mitigation
Update Masteriyo LMS to version 2.2.1 or later which includes proper authorization checks on the course-progress REST API endpoint.
EPSS Score
0.28%
Probability of exploitation in next 30 days
20.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.