MEDIUM

CVE-2026-10824

2026-06-25 CVSS v3.1
CVSS
6.5

Description

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.

Summary dbcve.org

The Masteriyo LMS WordPress plugin before version 2.2.1 has a broken access control vulnerability in its course-progress REST API controller. The endpoint lacks authorization checks, enabling any unauthenticated user to read and permanently delete any user's course-progress records via direct object reference.

Mitigation

Update Masteriyo LMS to version 2.2.1 or later which includes proper authorization checks on the course-progress REST API endpoint.

EPSS Score

0.28%
Probability of exploitation in next 30 days
20.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE