PT-2026-97709 · WordPress · Masteriyo - Lms

·

CVE-2026-82849

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Masteriyo LMS versions prior to 3.4.2
Description An Insecure Direct Object Reference (IDOR) exists where the software fails to verify if the authenticated user requesting course-progress records is the actual owner of those records. This allows any authenticated user, including self-registered subscribers, to access the learning activity of other users. Furthermore, if the requested account is not specified with a non-zero value, the system skips the ownership check entirely and returns the progress records of all learners on the site.
Recommendations Update Masteriyo LMS to version 3.4.2 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82849

Affected Products

Masteriyo - Lms