CVE-2026-62132: WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Masteriyo - LMSto a version that resolves this vulnerability.Fixed in 3.4.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as subscriber broken access control, indicating that a WordPress user with the Subscriber role is the relevant attacker category. The supplied severity vector also lists no privileges required, but the description specifically identifies Subscriber access.
What is the potential impact?
The provided severity vector indicates low integrity impact and no confidentiality or availability impact. This means the reported consequence is unauthorized modification rather than data disclosure or service disruption.
Which versions are affected?
Masteriyo - LMS plugin versions 3.4.0 and earlier are identified as affected. The supplied data does not specify a fixed version or workaround.