WordPress Plugin Vulnerabilities

Masteriyo LMS < 2.2.1 - Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion

Description

The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Jamshed Yergashvoyev (CVE Guy)
Verified
No

Timeline

Publicly Published
2026-09-06 (about 8 days ago)
Added
2026-09-07 (about 7 days ago)
Last Updated
2026-09-07 (about 6 days ago)

Other