CVE-2026-82851: Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Masteriyo LMS (WordPress plugin)to a version that resolves this vulnerability.Fixed in 3.4.1
Event History
Frequently Asked Questions
Which users can exploit this issue?
Users with the Masteriyo instructor role can exploit it. The issue allows an instructor to retrieve records belonging to other instructors.
What data can be disclosed?
An affected instructor can retrieve the full content and metadata of arbitrary posts. This includes private and draft courses created by other instructors.
Which versions are affected and what version fixes it?
Masteriyo LMS versions 1.14.0 through 3.4.0 are affected. Version 3.4.1 addresses the issue.