CVE-2025-54699: WordPress Masteriyo - LMS Plugin plugin <= 1.18.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS allows Stored XSS. This issue affects Masteriyo - LMS: from n/a through 1.18.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54699?
CVE-2025-54699 is classified as a significant vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2025-54699?
To fix CVE-2025-54699, update the Masteriyo - LMS or Masteriyo - LMS Plugin to version 1.18.4 or higher.
What systems are affected by CVE-2025-54699?
CVE-2025-54699 impacts Masteriyo - LMS versions up to 1.18.3, including the WordPress Masteriyo - LMS Plugin.
What type of vulnerability is CVE-2025-54699?
CVE-2025-54699 is an Improper Neutralization of Input During Web Page Generation, commonly known as a Stored Cross-site Scripting (XSS) vulnerability.
Can I identify if my application is vulnerable to CVE-2025-54699?
You can identify if your application is vulnerable to CVE-2025-54699 by checking if you are using Masteriyo - LMS or its plugin at version 1.18.3 or earlier.