CVE-2026-82848: Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure

Published Sep 9, 2026
·
Updated

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.

Affected Software

1 affected component
Masteriyo Masteriyo LMS WordPress plugin<3.4.0

Event History

Sep 9, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can access the exposed enrollment information?

Unauthenticated users can retrieve learner enrollment records through the REST API. Enrolled users can also retrieve enrollment records belonging to other learners.

2

What information can be obtained, and how is it accessed?

The exposed records include enrollment status, timestamps, and course-progress data. An attacker can enumerate records by walking sequential enrollment record identifiers.

3

Which deployments are affected?

The issue affects Masteriyo LMS WordPress plugin versions before 3.4.0, including the stated affected range of 1.3.1 through 2.3.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203