SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-82847

MEDIUM · CVSS 6.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Masteriyo LMS WordPress plugin prior to version 3.4.1 is vulnerable due to inadequate sanitization and escaping of course fields, enabling instructors to execute Stored Cross-Site Scripting (XSS) attacks on higher-privileged users, including administrators. This vulnerability poses a significant risk as it can lead to unauthorized access and manipulation of sensitive data. WordPress site administrators and users of the Masteriyo LMS plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-82847
Severity
MEDIUM
CVSS
6.8
EPSS
0.24%
WordPress

Original NVD Description

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.