Junglewise Threat Intelligence

CVE-2026-59513: Masteriyo LMS Subscriber Cross Site Scripting

CVE-2026-59513 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Vendors: Masteriyo.

Executive brief

Masteriyo - LMS is a WordPress plugin used to create and manage online learning courses. A security vulnerability in versions 2.3.0 and earlier allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another user views the affected content, these scripts could be used to redirect visitors to malicious sites, display unauthorized advertisements, or potentially compromise user sessions.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Masteriyo - LMS plugin for WordPress (versions <= 2.3.0) due to improper neutralization of input during web page generation. An attacker with Subscriber-level privileges can inject malicious JavaScript payloads into the application. Because the vulnerability is 'Stored' or 'Reflected' with a scope change (S:C), the script executes in the context of other users, including administrators, when they interact with the affected page. This requires minimal user interaction (viewing a page) and is reachable over the network. The issue is resolved in version 2.3.1.

Affected products

  • Masteriyo Masteriyo - LMS <= 2.3.0

Timeline

  • 2026-06-26: other: Reported by K. Sorrachat
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD
  • 2026-07-21: patched: Version 2.3.1 released to address the vulnerability

References