SecAlerts
Masteriyo logo

Masteriyo

Security Risk Profile

30
/100
low

Security Risk Score

Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from July 31, 2023 to present

12
Total CVEs
5
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
30/100
low

Severity Distribution

Critical
1
High
4
Medium
7
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
2
2
Infoleak
1

Most Affected Products

1. masteriyo Masteriyo - LMS4
2. themegrill Masteriyo Wordpress3
3. WordPress Masteriyo LMS plugin3
4. masteriyo Masteriyo WordPress3
5. Masteriyo Masteriyo WordPress3

Recent Vulnerabilities

See more →
CVE-2026-11773
CVSS 4.3medium

Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification

6/27/2026🔧 No Patch
CVE-2026-5167
CVSS 5.3EPSS 0%medium

Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint

4/8/2026🔧 No Patch
CVE-2026-4484
CVSS 8.8EPSS 0%high

Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

3/26/2026🔧 No Patch
CVE-2025-54699
CVSS 6.5medium

WordPress Masteriyo - LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) Vulnerability

8/14/2025
CVE-2024-33939
CVSS 5.3medium

WordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability

5/19/2025
CVE-2024-43158
CVSS 7.5high

WordPress Masteriyo LMS plugin <= 1.11.4 - Broken Access Control vulnerability

11/1/2024
CVE-2024-43159
CVSS 5.3medium

WordPress Masteriyo LMS plugin <= 1.11.6 - Broken Access Control vulnerability

11/1/2024
CVE-2024-10000
CVSS 6.4medium

Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Stored Cross-Site Scripting via Ask a Question Functionality

10/29/2024🔧 No Patch
CVE-2024-10008
CVSS 8.8high

Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation

10/29/2024🔧 No Patch
CVE-2024-43239
CVSS 8.1high

WordPress Masteriyo LMS plugin <= 1.11.4 - Insecure Direct Object Reference (IDOR) vulnerability

8/18/2024

Monitor Masteriyo in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

Masteriyo Security Vulnerabilities & Risk Score | 12 CVEs | SecAlerts - SecAlerts