CVE-2026-82848: Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.
Affected Software
Event History
Frequently Asked Questions
Who can access the exposed enrollment information?
Unauthenticated users can retrieve learner enrollment records through the REST API. Enrolled users can also retrieve enrollment records belonging to other learners.
What information can be obtained, and how is it accessed?
The exposed records include enrollment status, timestamps, and course-progress data. An attacker can enumerate records by walking sequential enrollment record identifiers.
Which deployments are affected?
The issue affects Masteriyo LMS WordPress plugin versions before 3.4.0, including the stated affected range of 1.3.1 through 2.3.3.