Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Masteriyo
Masteriyo masteriyo Lms – Lms Course Builder, Quizzes & Certificates Wordpress Wordpress wordpress |
|
| Vendors & Products |
Masteriyo
Masteriyo masteriyo Lms – Lms Course Builder, Quizzes & Certificates Wordpress Wordpress wordpress |
Mon, 07 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student. | |
| Title | Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-08T14:45:40.841Z
Reserved: 2026-05-11T04:57:04.257Z
Link: CVE-2026-8279
Updated: 2026-09-08T14:45:37.911Z
Status : Deferred
Published: 2026-09-07T13:20:43.560
Modified: 2026-09-08T15:18:56.237
Link: CVE-2026-8279
No data.
OpenCVE Enrichment
Updated: 2026-09-07T16:30:06Z