CVE-2026-8279: Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'deleteitempermissionscheck' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it remotely; no WordPress account or prior privileges are required.
What data can be affected?
Attackers can delete arbitrary course progress records belonging to any student. The provided information indicates an integrity impact, not disclosure of information or service availability impact.
Which installations are affected?
Masteriyo LMS versions up to and including 2.2.0 are affected. The issue is in the course-progress REST controller's deletion permission check.
How can I tell whether my site is exposed?
Check the installed Masteriyo LMS version. Sites running version 2.2.0 or an earlier version are affected according to the available data.