CVE-2026-82847: CWE-79 Cross-Site Scripting (XSS) in Masteriyo LMS
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
AI Analysis
Technical Summary
CVE-2026-82847 is a stored XSS vulnerability in the Masteriyo LMS WordPress plugin prior to version 3.4.1. The vulnerability occurs due to improper sanitization and escaping of a course field before rendering it in the course editor interface. Users with the instructor role can exploit this to inject malicious scripts that execute when administrators or other privileged users view the affected course content, potentially leading to session hijacking or other script-based attacks.
Potential Impact
Users with the instructor role can perform stored XSS attacks against administrators or other higher privileged users by injecting malicious scripts into a course field. This could lead to unauthorized actions performed by administrators, theft of sensitive information, or compromise of administrative accounts. The vulnerability affects the confidentiality and integrity of the affected WordPress site.
Mitigation Recommendations
Upgrade the Masteriyo LMS plugin to version 3.4.1 or later, where this vulnerability is fixed. There is no indication that any temporary or alternative mitigations exist, so applying the official update is required to remediate the issue.
CVE-2026-82847: CWE-79 Cross-Site Scripting (XSS) in Masteriyo LMS
Description
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
CVSS v3.1
Score 6.8medium
Affected software
Masteriyo LMS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-82847 is a stored XSS vulnerability in the Masteriyo LMS WordPress plugin prior to version 3.4.1. The vulnerability occurs due to improper sanitization and escaping of a course field before rendering it in the course editor interface. Users with the instructor role can exploit this to inject malicious scripts that execute when administrators or other privileged users view the affected course content, potentially leading to session hijacking or other script-based attacks.
Potential Impact
Users with the instructor role can perform stored XSS attacks against administrators or other higher privileged users by injecting malicious scripts into a course field. This could lead to unauthorized actions performed by administrators, theft of sensitive information, or compromise of administrative accounts. The vulnerability affects the confidentiality and integrity of the affected WordPress site.
Mitigation Recommendations
Upgrade the Masteriyo LMS plugin to version 3.4.1 or later, where this vulnerability is fixed. There is no indication that any temporary or alternative mitigations exist, so applying the official update is required to remediate the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-31T08:27:25.822Z
- State
- PUBLISHED
Threat ID: 6aa4ee6155bf5e2cf5f21fe8
Added to database: 09/12/2026, 06:17:05 UTC
Last enriched: 09/12/2026, 06:47:48 UTC
Last updated: 09/13/2026, 02:06:04 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.