N/A
2026-04-08< 2.1.6
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 - Missing Authorization
Minimum safe version
2.1.8
Update to 2.1.8 or later to address 15 fixable vulnerabilities
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education <= 2.1.5 - Missing Authorization
Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator
Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint
CVE-2025-64270
CVE-2025-54699
CVE-2024-10000
CVE-2024-10008
CVE-2024-43239
CVE-2024-43158
CVE-2024-43159
CVE-2024-33939
CVE-2024-24882
CVE-2023-3345
WordPress Masteriyo - LMS Plugin < 1.6.8 is vulnerable to Sensitive Data Exposure
Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure