{"id":"CVE-2026-82851","title":"The Masteriyo LMS  WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitr…","summary":"The Masteriyo LMS  WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitr…","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"product":"Masteriyo LMS","affected":["masteriyo_lms >= 1.14.0 < 3.4.1"],"published":"2026-09-12","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82851","references":[{"url":"https://wpscan.com/vulnerability/07664081-72c3-4f7e-9324-e0047b6e6d22/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00179,"epssPercentile":0.07685,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-12T15:21:28.698575Z"},"ingestedAt":"2026-09-14T15:23:07.478Z","slug":"CVE-2026-82851","body":"## Overview\n\nThe Masteriyo LMS  WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}