Executive brief
Masteriyo is a Learning Management System (LMS) plugin for WordPress used to create and sell online courses. A security flaw in versions 2.1.8 and earlier allows unauthorized individuals to bypass authentication mechanisms. This could allow an attacker to perform administrative actions or gain full control over the website, potentially leading to the theft of student data or disruption of course delivery.
Technical details
The Masteriyo - LMS plugin for WordPress (versions <= 2.1.8) contains a broken authentication vulnerability, specifically related to improper verification of cryptographic signatures (CWE-347). This flaw allows an unauthenticated remote attacker to bypass security checks and potentially perform actions with elevated privileges. The vulnerability is exploitable over the network without user interaction. Successful exploitation could lead to unauthorized access to administrative functions or account takeover. The issue is resolved in version 2.1.9.
Affected products
- ThemeGrill Masteriyo - LMS <= 2.1.8
Timeline
- 2026-04-28: other: Reported by researcher HieuPenguinnn
- 2026-05-28: advisory: Initial disclosure by Patchstack
- 2026-06-15: disclosed: CVE published to NVD
- 2026-06-15: patched: Patch available in version 2.1.9