Junglewise Threat Intelligence

CVE-2026-65463: ThemeGrill Masteriyo LMS IDOR in versions up to 2.3.1

CVE-2026-65463 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Technologies: ThemeGrill Masteriyo - LMS. Vendors: ThemeGrill.

Executive brief

Masteriyo is a Learning Management System (LMS) plugin for WordPress used to create and manage online courses. A security flaw in versions 2.3.1 and earlier allows logged-in users with basic 'Subscriber' permissions to access or modify data they should not have permission to reach. This could lead to unauthorized changes to course content or database records, potentially disrupting educational operations.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Masteriyo - LMS plugin for WordPress (versions <= 2.3.1). The flaw is rooted in insufficient authorization checks when handling user-controlled keys or object identifiers. An attacker authenticated with Subscriber-level privileges can exploit this by manipulating input parameters to interact with unauthorized objects or database records. This can result in unauthorized data modification or integrity loss. The issue is resolved in version 2.3.2.

Affected products

  • ThemeGrill Masteriyo - LMS <= 2.3.1

Timeline

  • 2026-07-01: disclosed: Reported by Celvex Group
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: patched: Version 2.3.2 released to address the vulnerability

References

Related threats