CVE-2026-82847: Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights
Published Sep 12, 2026
·Updated
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
Affected Software
1 affected component
Masteriyo Masteriyo LMS WordPress plugin<3.4.1
Event History
Sep 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which users can exploit this issue, and who is at risk from the payload?
A user with the instructor role can inject stored script through the affected course field. The payload is executed when viewed in the course editor by a higher-privileged user, such as an administrator.
2
What version should be used to remediate the issue?
Upgrade Masteriyo LMS to version 3.4.1 or later. Versions before 3.4.1 are affected.