Unauthorized Data Deletion in Masteriyo LMS Plugin for WordPress
CVE-2026-8279
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 September 2026
What is CVE-2026-8279?
The Masteriyo LMS plugin for WordPress has a security flaw allowing unauthorized data deletion due to an absence of proper capability checks in its CourseProgressItemsController. As a result, unauthenticated attackers can exploit this vulnerability to delete course progress records for any student. All versions up to and including 2.2.0 are affected, posing a significant risk to user data integrity.
Affected Version(s)
Masteriyo LMS β LMS Course Builder, Quizzes & Certificates 0 <= 2.2.0