CVE-2026-82847: The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting
infovulnerability
security
Summary
The Masteriyo LMS WordPress plugin before version 3.4.1 has a security flaw where it fails to sanitize and escape (clean and safely format) user input in a course field before displaying it back in the editor. This allows instructors to inject malicious scripts (stored XSS, or persistent code that targets other users) that can affect administrators and other high-privilege users.
Solution / Mitigation
Update the Masteriyo LMS WordPress plugin to version 3.4.1 or later.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 12, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82847
First tracked: September 12, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%