CVE-2026-19712: The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in
Summary
The Masteriyo LMS WordPress plugin before version 2.3.3 has a stored cross-site scripting (XSS, an attack where malicious code is saved and runs when others view a page) vulnerability. Instructors can store unfiltered HTML in a quiz field, which then executes in visitors' browsers when they view that page, potentially compromising accounts including administrators. Single-site WordPress installations with default settings are affected, but multisite installations and those with DISALLOW_UNFILTERED_HTML enabled are protected.
Solution / Mitigation
Update the Masteriyo LMS WordPress plugin to version 2.3.3 or later.
Vulnerability Details
EPSS: 0.0%
August 16, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19712
First tracked: August 16, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 95%