PT-2026-73123 · WordPress · Masteriyo - Lms

·

CVE-2026-19712

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Masteriyo LMS versions prior to 2.3.3
Description The plugin fails to sanitize and escape a quiz field before outputting it on a page. This allows users with the instructor role to store unfiltered HTML, enabling Stored Cross-Site Scripting (XSS) attacks—a technique where malicious scripts are permanently stored on the server and executed in the browser of any visitor, including administrators. This issue affects default single-site installations; however, multisite installations or sites that define DISALLOW UNFILTERED HTML are not affected.
Recommendations Update Masteriyo LMS to version 2.3.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19712

Affected Products

Masteriyo - Lms