WordPress Plugin Vulnerabilities

Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields

Description

The plugin does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Mutantgun
Submitter
Mutantgun
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 22 hours ago)
Added
2026-09-03 (about 8 hours ago)
Last Updated
2026-09-03 (about 8 hours ago)

Other