WordPress Plugin Vulnerabilities

Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR

Description

The plugin does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-22 (about 2 days ago)
Added
2026-09-22 (about 1 day ago)
Last Updated
2026-09-22 (about 1 day ago)

Other