Vulnerability Brief
CVE-2026-11773
What this means for your business
If a hacker exploits this vulnerability in the WordPress plugin, they could potentially make unauthorized changes to sensitive information on your website, such as course announcements. This could lead to compromised data, damaged credibility, and lost business, especially if you rely on your website for online courses or training services. To protect your business, it's essential to update the plugin to a secure version and consider implementing additional security measures to prevent similar attacks in the future.
- Severity: MEDIUM
- CVSS score: 4.3
Technical summary
The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with student-level access and above, to modify the description (post content) of arbitrary course announcements authored by instructors or administrators.