Junglewise Threat Intelligence

CVE-2026-42743: ThemeGrill Masteriyo LMS broken authentication

CVE-2026-42743 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: ThemeGrill Masteriyo - LMS. Vendors: ThemeGrill.

Executive brief

Masteriyo is a Learning Management System (LMS) plugin for WordPress used to create and sell online courses. A security flaw in versions 2.1.8 and earlier allows unauthorized individuals to bypass authentication mechanisms. This could allow an attacker to perform administrative actions or gain full control over the website, potentially leading to the theft of student data or disruption of course delivery.

Technical details

The Masteriyo - LMS plugin for WordPress (versions <= 2.1.8) contains a broken authentication vulnerability, specifically related to improper verification of cryptographic signatures (CWE-347). This flaw allows an unauthenticated remote attacker to bypass security checks and potentially perform actions with elevated privileges. The vulnerability is exploitable over the network without user interaction. Successful exploitation could lead to unauthorized access to administrative functions or account takeover. The issue is resolved in version 2.1.9.

Affected products

  • ThemeGrill Masteriyo - LMS <= 2.1.8

Timeline

  • 2026-04-28: other: Reported by researcher HieuPenguinnn
  • 2026-05-28: advisory: Initial disclosure by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-06-15: patched: Patch available in version 2.1.9

References

Related threats