Executive brief
Masteriyo is a Learning Management System (LMS) plugin for WordPress used to create and manage online courses. A security flaw in versions 2.3.1 and earlier allows logged-in users with basic 'Subscriber' permissions to access or modify data they should not have permission to reach. This could lead to unauthorized changes to course content or database records, potentially disrupting educational operations.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the Masteriyo - LMS plugin for WordPress (versions <= 2.3.1). The flaw is rooted in insufficient authorization checks when handling user-controlled keys or object identifiers. An attacker authenticated with Subscriber-level privileges can exploit this by manipulating input parameters to interact with unauthorized objects or database records. This can result in unauthorized data modification or integrity loss. The issue is resolved in version 2.3.2.
Affected products
- ThemeGrill Masteriyo - LMS <= 2.3.1
Timeline
- 2026-07-01: disclosed: Reported by Celvex Group
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: patched: Version 2.3.2 released to address the vulnerability