PT-2026-64837 · WordPress · Masteriyo - Lms

·

CVE-2026-13332

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Masteriyo LMS WordPress plugin versions prior to 2.3.1
Description An issue exists where the software fails to correctly verify authorization on an unauthenticated AJAX action used to clear user sessions. This allows unauthenticated attackers to terminate the active sessions, resulting in a force-logout of any user on the site, including administrators.
Recommendations Update the Masteriyo LMS WordPress plugin to version 2.3.1 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13332

Affected Products

Masteriyo - Lms