---
id: CVE-2026-82847
title: >-
  The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and escape
  one of its course fields before outputting it back in the course editor,
  allowing users with the instructor role to perform Stored Cross-Site Scripting
  attacks…
summary: >-
  The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and escape
  one of its course fields before outputting it back in the course editor,
  allowing users with the instructor role to perform Stored Cross-Site Scripting
  attacks…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Masteriyo LMS
affected:
  - masteriyo_lms < 3.4.1
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82847'
references:
  - url: 'https://wpscan.com/vulnerability/9cc4f7a7-e5b9-48fe-962b-f5d0753e6158/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00431
epssPercentile: 0.34618
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-12T15:21:51.334502Z'
ingestedAt: '2026-09-14T15:23:07.478Z'
---

## Overview

The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
