Executive brief
Themeisle Masteriyo LMS PRO, a WordPress plugin used for creating and managing online courses, contains a critical security flaw that allows unauthorized users to gain administrative control. An attacker can exploit this to take over the website, potentially accessing sensitive student data, modifying course content, or disrupting business operations. This vulnerability is highly dangerous as it requires no prior account or special access to execute.
Technical details
An Incorrect Privilege Assignment vulnerability (CWE-266) exists in the Themeisle Masteriyo LMS PRO plugin for WordPress through version 2.20.0. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining administrator-level access to the affected site. The vulnerability is exploitable over the network with low complexity and requires no user interaction. A patch is available in version 2.20.1, which addresses the improper assignment of user roles or permissions.
Affected products
- Themeisle Masteriyo LMS PRO <= 2.20.0
Timeline
- 2025-06-11: other: Reported by researcher 0xd4rk5id3
- 2025-07-01: disclosed: Initial disclosure by Patchstack
- 2025-07-01: patched: Version 2.20.1 released to address the vulnerability
- 2026-06-02: advisory: NVD publication date