CVE-2026-82846
N/A
N/A
Summary
The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Masteriyo LMS | 1.18.0 < 3.4.0 | affected |
Weaknesses
- CWE-79 Cross-Site Scripting (XSS)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.