Junglewise Threat Intelligence

CVE-2026-62132: Masteriyo LMS broken access control in subscriber pages

CVE-2026-62132 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Technologies: ThemeGrill Masteriyo - LMS. Vendors: ThemeGrill.

Executive brief

Masteriyo is a learning management system plugin for WordPress that allows organizations to create and manage online courses. The plugin contains an access control flaw that allows subscribers to view or access pages and content they should not have permission to see, potentially exposing sensitive course materials or other users' data.

Technical details

The vulnerability is a broken access control issue in Masteriyo LMS versions 3.4.0 and earlier. Subscribers with basic permissions can bypass authorization checks to access restricted pages or perform actions reserved for higher-privilege roles. The attack requires only subscriber-level authentication (no elevated privileges needed) and is exploitable over the network. An attacker with a subscriber account can view unauthorized course content or access other users' data. The vulnerability was patched in version 3.4.1.

Affected products

  • ThemeGrill Masteriyo - LMS 3.4.0 and earlier

Timeline

  • 2026-09-10: disclosed: Published by Patchstack
  • 2026-09-10: patched: Version 3.4.1 released

References

Related threats