WordPress Plugin Vulnerabilities

Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description

Description

The plugin does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators.
This affects default single-site installations. Sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-14 (about 2 days ago)
Added
2026-08-14 (about 1 day ago)
Last Updated
2026-08-14 (about 1 day ago)

Other