Cross Site Scripting Vulnerability in Masteriyo Learning Management System
CVE-2026-59513

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-59513?

A security flaw has been identified in the Masteriyo Learning Management System that allows for Subscriber Cross Site Scripting attacks. This vulnerability affects versions up to 2.3.0, enabling attackers to inject malicious scripts into webpages viewed by users. As a result, unauthorized access and data theft can occur if proper security measures are not implemented. Users of Masteriyo LMS should take immediate action to update their software and safeguard their sites from potential exploitation.

Affected Version(s)

Masteriyo - LMS <= 2.3.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

K. Sorrachat | Patchstack Bug Bounty Program
.