Junglewise Threat Intelligence

CVE-2026-82851: Masteriyo LMS arbitrary post disclosure via IDOR

CVE-2026-82851 · Severity: low · CVSS 2.7 · Published 2026-09-12

Technologies: Masteriyo LMS. Vendors: Masteriyo.

Executive brief

Masteriyo LMS is a WordPress learning management system plugin used to create and deliver online courses. The plugin failed to properly verify access permissions when users requested course exports, allowing instructors to download private and draft courses belonging to other instructors, along with sensitive metadata including pricing and video URLs. This enables unauthorized access to competitive course content and confidential course materials.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the course export endpoint (/wp-json/masteriyo/v1/courses/export). The plugin accepts a POST request with a list of course IDs to export but does not verify that the requesting user owns those courses or has permission to access them. An authenticated user with the Instructor role can export any post or course by ID regardless of ownership or publication status. The attack requires an authenticated instructor account and a valid REST nonce, allowing attackers to retrieve the full post content, all metadata, and sensitive information such as course status, author details, and video source URLs. The vulnerability was fixed in version 3.4.1.

Affected products

  • Masteriyo LMS 1.14.0 to 3.4.0

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: patched: Fixed in version 3.4.1

References