THREAT OPS › Threat News › [NVD] CVE-2026-82851 (LOW 2.7) — The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' pri
[NVD] CVE-2026-82851 (LOW 2.7) — The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' pri
CVE-2026-82851 CVSS: 2.7 LOW Published: 2026-09-12T06:16:26.253
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.
Indicators of compromise
- CVE-2026-82851cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82851