PT-2026-73123 · WordPress · Masteriyo - Lms
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Masteriyo LMS versions prior to 2.3.3
Description
The plugin fails to sanitize and escape a quiz field before outputting it on a page. This allows users with the instructor role to store unfiltered HTML, enabling Stored Cross-Site Scripting (XSS) attacks—a technique where malicious scripts are permanently stored on the server and executed in the browser of any visitor, including administrators. This issue affects default single-site installations; however, multisite installations or sites that define
DISALLOW UNFILTERED HTML are not affected.Recommendations
Update Masteriyo LMS to version 2.3.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Masteriyo - Lms