Junglewise Threat Intelligence

CVE-2026-49111: ThemeGrill Masteriyo LMS privilege escalation

CVE-2026-49111 · Severity: high · CVSS 8.8 · Published 2026-06-15

Technologies: ThemeGrill Masteriyo - LMS. Vendors: ThemeGrill.

Executive brief

ThemeGrill Masteriyo, a popular Learning Management System (LMS) plugin for WordPress, contains a security flaw that allows users with low-level access to gain administrative control. By exploiting this vulnerability, a malicious user could take over the entire website, potentially leading to data theft, site defacement, or complete service disruption. This is particularly critical for educational platforms that handle student data and course content.

Technical details

An Incorrect Privilege Assignment vulnerability (CWE-266) exists in the ThemeGrill Masteriyo - LMS plugin for WordPress through version 2.2.0. The flaw allows an authenticated attacker with basic 'Subscriber' level permissions to escalate their privileges to a higher level, potentially reaching administrative status. This is achieved via a network-based attack with low complexity and no user interaction required. Successful exploitation grants the attacker full control over the WordPress environment. The issue is addressed in version 2.2.1.

Affected products

  • ThemeGrill Masteriyo - LMS up to 2.2.0

Timeline

  • 2026-05-12: other: Reported by researcher daroo
  • 2026-06-08: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-06-08: patched: Version 2.2.1 released to address the issue

References