MEDIUM 5.3 NVD
CVE-2026-8279
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' func
The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student.
References
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.9/includes/
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.9/includes/
- https://plugins.trac.wordpress.org/browser/learning-management-system/tags/2.1.9/includes/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d317d40b-2b99-408b-b445-1a789df3
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-07 via NVD.
vulnfeed aggregates 2664 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.