Executive brief
Masteriyo LMS, a learning management system plugin for WordPress, contains a security flaw that allows unauthorized individuals to force other users to log out. By exploiting an unprotected session management feature, an attacker can repeatedly terminate the active sessions of any user, including site administrators. This results in a denial of service for legitimate users, disrupting their ability to access the platform or perform administrative tasks.
Technical details
The Masteriyo LMS plugin fails to implement proper authorization checks on the 'masteriyo_clear_sessions' AJAX action. An unauthenticated attacker can obtain a valid session-clearing nonce by triggering a session limit warning via the 'masteriyo_login' action using a known username. Once the nonce is obtained, the attacker can send a POST request to 'admin-ajax.php' targeting a specific 'user_id' to destroy all active session tokens for that user. This vulnerability effectively allows for unauthenticated arbitrary user session termination, leading to a targeted denial of service. The issue is fixed in version 2.3.1.
Affected products
- Masteriyo Masteriyo LMS < 2.3.1
Timeline
- 2026-07-06: disclosed: Publicly published by WPScan
- 2026-07-27: advisory: CVE published to NVD dataset
- 2026-07-27: patched: Fixed in version 2.3.1