CVE-2026-4484

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator.
Configurations

No configuration.

History

08 Apr 2026, 17:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.8

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) El plugin Masteriyo LMS para WordPress es vulnerable a una escalada de privilegios en todas las versiones hasta la 2.1.6, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el rol de usuario a través de la función 'InstructorsController::prepare_object_for_database'. Esto hace posible que atacantes autenticados, con acceso de nivel de Estudiante o superior, eleven sus privilegios a los de un administrador.

26 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 02:16

Updated : 2026-04-08 17:21


NVD link : CVE-2026-4484

Mitre link : CVE-2026-4484

CVE.ORG link : CVE-2026-4484


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization