Executive brief
Masteriyo LMS is a WordPress plugin for managing online courses and student learning. The plugin fails to properly verify user permissions when deleting course progress records, allowing unauthenticated attackers to delete any student's progress data. This could disrupt course tracking, student grades, and learning outcomes without detection or authorization.
Technical details
The vulnerability is an authorization bypass (missing capability check) in the CourseProgressItemsController's delete_item_permissions_check function. Unauthenticated attackers can directly call the deletion endpoint to remove arbitrary course progress records via the REST API, without requiring authentication or admin privileges. The vulnerability affects the plugin through version 2.2.0. The root cause is insufficient permission validation before executing destructive operations on student progress data. An attacker needs only network access to the WordPress site and can arbitrarily target and delete course progress belonging to any student.
Affected products
- Masteriyo Masteriyo LMS up to and including 2.2.0
Timeline
- 2026-09-07: disclosed