CVE-2026-82850: Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure
The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses they are not enrolled in. The redaction that hides them is applied only to a fixed list of question types, so the answers to every other type are returned in full to anyone able to view the questions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Masteriyo LMSto a version that resolves this vulnerability.Fixed in 3.4.2
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user, including a subscriber or student account, can retrieve quiz answer keys. The user does not need to be enrolled in the course containing the quiz.
Are all quiz question types affected?
Answer hiding is applied only to a fixed list of question types. Correct answers for question types outside that list are returned in full to authenticated users who can view the questions.
How can I determine whether my site is vulnerable?
Sites using Masteriyo LMS versions before 3.4.2 are affected. Test with a low-privilege authenticated account by viewing quiz questions, including quizzes for courses in which that account is not enrolled, and check whether answer keys are returned.