masteriyo has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.3 (medium). Most affected products: learning-management-system (2), Masteriyo LMS – LMS Course Builder, Quizzes & Certificates (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- learning-management-system 2
- Masteriyo LMS – LMS Course Builder, Quizzes & Certificates 1
Worst active — by depth score
CVE-2026-62107High· 8.8WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability48CVE-2026-62132Medium· 5.3WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability29CVE-2026-8279Medium· 5.3The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and includin…29
masteriyo vulnerabilities
CVEs affecting masteriyo, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-62132Medium· 5.3WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-62107High· 8.8WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-8279Medium· 5.3The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and includin…
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and includin…