Executive brief
Masteriyo is a learning management system plugin for WordPress that allows organizations to create and manage online courses. The plugin contains an access control flaw that allows subscribers to view or access pages and content they should not have permission to see, potentially exposing sensitive course materials or other users' data.
Technical details
The vulnerability is a broken access control issue in Masteriyo LMS versions 3.4.0 and earlier. Subscribers with basic permissions can bypass authorization checks to access restricted pages or perform actions reserved for higher-privilege roles. The attack requires only subscriber-level authentication (no elevated privileges needed) and is exploitable over the network. An attacker with a subscriber account can view unauthorized course content or access other users' data. The vulnerability was patched in version 3.4.1.
Affected products
- ThemeGrill Masteriyo - LMS 3.4.0 and earlier
Timeline
- 2026-09-10: disclosed: Published by Patchstack
- 2026-09-10: patched: Version 3.4.1 released