CVE-2026-82851: The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a us
infovulnerability
security
Summary
The Masteriyo LMS WordPress plugin before version 3.4.1 has a security flaw where it doesn't check if a user actually owns the content they're trying to download or limit what type of files they can access. This means instructors can download other instructors' private and draft courses, including all their content and metadata (information about the courses).
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 12, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82851
First tracked: September 12, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%