{"id":"CVE-2026-8279","title":"The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and includin…","summary":"The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and includin…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"masteriyo","product":"Masteriyo LMS – LMS Course Builder, Quizzes & Certificates","affected":["lms_lms_course_builder_quizzes_certificates <= 2.2.0"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T15:18:56.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8279","references":[{"url":"https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.9/includes/Repository/CourseProgressItemRepository.php#L269","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.9/includes/RestApi/Controllers/Version1/CourseProgressItemsController.php#L124","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.9/includes/RestApi/Controllers/Version1/CourseProgressItemsController.php#L805","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d317d40b-2b99-408b-b445-1a789df3c958?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T14:45:34.295690Z"},"epss":0.00235,"epssPercentile":0.14686,"ingestedAt":"2026-09-08T15:33:26.977Z","slug":"CVE-2026-8279","body":"## Overview\n\nThe Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}