Executive brief
Masteriyo LMS is a WordPress plugin used to create and manage online courses, quizzes, and student certifications. A security flaw in the plugin allows users with basic student-level accounts to modify course announcements that were originally created by instructors or administrators. This could lead to the spread of misinformation or unauthorized changes to course communications, potentially damaging the reputation of the educational institution.
Technical details
The Masteriyo LMS plugin for WordPress (versions up to 2.2.1) contains a missing authorization vulnerability (CWE-862) within the CourseAnnouncementController.php component. The plugin fails to adequately verify if a user has the necessary permissions before allowing updates to course announcement post content. An authenticated attacker with student-level privileges can exploit this by sending a crafted request to modify the description of arbitrary announcements. This vulnerability is accessible over the network and does not require user interaction, though it does require valid authentication. A patch is available in versions following 2.2.1.
Affected products
- Masteriyo Masteriyo LMS – LMS Course Builder, Quizzes & Certificates up to, and including, 2.2.1
Timeline
- 2026-06-27: disclosed: CVE published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.8/addons/course-announcement/Controllers/CourseAnnouncementController.php
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.8/addons/course-announcement/Controllers/CourseAnnouncementController.php
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.2.1/addons/course-announcement/Controllers/CourseAnnouncementController.php
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.2.1/addons/course-announcement/Controllers/CourseAnnouncementController.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3583519%40learning-management-system&new=3583519%40learning-management-system&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5780d762-2313-4c81-be02-99543359d824?source=cve