What the vulnerability does
01Description
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it possible for authenticated attackers, with student-level access and above, to modify the roles of arbitrary users. As a result, attackers can escalate their privileges to the Administrator and demote existing administrators to students.
Explanation of Vulnerability in Simple Terms
02Summary
Masteriyo LMS versions up to 1.13.3 lack proper authorization checks, allowing authenticated users to perform actions they should not have permission to execute. An attacker with a low-privilege account can read, modify, or delete sensitive data and functionality across the platform. This affects confidentiality, integrity, and availability of course content and user information.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete course content and user data without proper authorization.
Potential impact on your site
04Site Impact
Unauthorized users can access, alter, or remove courses, student records, and other sensitive LMS data.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege user account on the site.
Key dates
06Disclosure timeline
October 29, 2024
CVE published
April 8, 2026
Record updated