CVE-2026-82849: CWE-639 Authorization Bypass Through User-Controlled Key in Masteriyo LMS
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.
AI Analysis
Technical Summary
CVE-2026-82849 is an authorization bypass vulnerability in the Masteriyo LMS WordPress plugin prior to version 3.4.2. The plugin fails to verify that the user requesting course-progress data owns those records. When the requested account is not named with a non-zero value, the ownership check is skipped, resulting in the exposure of all learners' progress records to any authenticated user.
Potential Impact
Any authenticated user on the affected WordPress site can access sensitive learning activity data of other users without proper authorization. This could lead to privacy violations and unauthorized disclosure of user progress information within the LMS.
Mitigation Recommendations
Upgrade Masteriyo LMS to version 3.4.2 or later, where this authorization bypass vulnerability has been fixed. No other mitigation is indicated.
CVE-2026-82849: CWE-639 Authorization Bypass Through User-Controlled Key in Masteriyo LMS
Description
The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another user's learning activity. The ownership check it applies is skipped whenever the requested account is not named with a non-zero value, in which case the records of every learner on the site are returned at once.
CVSS v3.1
Score 4.3medium
Affected software
Masteriyo LMS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-82849 is an authorization bypass vulnerability in the Masteriyo LMS WordPress plugin prior to version 3.4.2. The plugin fails to verify that the user requesting course-progress data owns those records. When the requested account is not named with a non-zero value, the ownership check is skipped, resulting in the exposure of all learners' progress records to any authenticated user.
Potential Impact
Any authenticated user on the affected WordPress site can access sensitive learning activity data of other users without proper authorization. This could lead to privacy violations and unauthorized disclosure of user progress information within the LMS.
Mitigation Recommendations
Upgrade Masteriyo LMS to version 3.4.2 or later, where this authorization bypass vulnerability has been fixed. No other mitigation is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-31T08:27:29.561Z
- State
- PUBLISHED
Threat ID: 6ab4c0b3f7a7c54106f3a83a
Added to database: 09/24/2026, 06:18:27 UTC
Last enriched: 09/24/2026, 06:33:56 UTC
Last updated: 09/25/2026, 01:56:02 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.