Junglewise Threat Intelligence

CVE-2026-39524: ThemeGrill Masteriyo LMS broken access control payment bypass

CVE-2026-39524 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: ThemeGrill Masteriyo - LMS. Vendors: ThemeGrill.

Executive brief

Masteriyo is a Learning Management System (LMS) plugin for WordPress used to create and sell online courses. A security flaw in versions 2.1.5 and earlier allows unauthorized users to bypass payment requirements or access restricted functions. This could result in financial loss for course creators as users may gain access to paid content without completing a purchase.

Technical details

The Masteriyo LMS plugin for WordPress (versions <= 2.1.5) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions that should be restricted to authorized or paying users. Specifically, the vulnerability is identified as a payment bypass, allowing users to potentially enroll in courses without valid transactions. The issue is resolved in version 2.1.6 by implementing proper server-side authorization checks.

Affected products

  • ThemeGrill Masteriyo - LMS <= 2.1.5

Timeline

  • 2026-02-17: disclosed: Reported by davidfdzmorilla
  • 2026-04-08: advisory: Patchstack published advisory
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-04-08: patched: Version 2.1.6 released to address the issue

References

Related threats