SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82848

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Masteriyo LMS plugin for WordPress prior to version 3.4.0 is vulnerable due to a lack of authorization checks in its REST API, enabling unauthenticated users to access sensitive course enrollment records, including learner status and progress data. Additionally, enrolled users can exploit this vulnerability to view other learners' enrollment details. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.

CVE
CVE-2026-82848
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.