Executive brief
Masteriyo LMS is a WordPress learning management system plugin used to create and deliver online courses. The plugin failed to properly verify access permissions when users requested course exports, allowing instructors to download private and draft courses belonging to other instructors, along with sensitive metadata including pricing and video URLs. This enables unauthorized access to competitive course content and confidential course materials.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the course export endpoint (/wp-json/masteriyo/v1/courses/export). The plugin accepts a POST request with a list of course IDs to export but does not verify that the requesting user owns those courses or has permission to access them. An authenticated user with the Instructor role can export any post or course by ID regardless of ownership or publication status. The attack requires an authenticated instructor account and a valid REST nonce, allowing attackers to retrieve the full post content, all metadata, and sensitive information such as course status, author details, and video source URLs. The vulnerability was fixed in version 3.4.1.
Affected products
- Masteriyo LMS 1.14.0 to 3.4.0
Timeline
- 2026-09-10: disclosed
- 2026-09-12: patched: Fixed in version 3.4.1