The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the CourseProgressItemsController in all versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to delete arbitrary course progress records belonging to any student.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 13:20
Updated : 2026-09-08 15:18
NVD link : CVE-2026-8279
Mitre link : CVE-2026-8279
CVE.ORG link : CVE-2026-8279
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
