CVEs
Vulnerability entries credited to me. Click a card to read the full description.
8 CVEs1 Critical1 High5 Medium1 Low
2026
-
CVE-2026-82851 LOW 2.7 Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR WordPress pluginMasteriyo LMS
The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.
-
CVE-2026-82847 MEDIUM 6.8 Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights WordPress pluginMasteriyo LMS
The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.
-
CVE-2026-82845 CRITICAL 9.9 Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection WordPress pluginMasteriyo LMS
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
-
CVE-2026-77705 HIGH 7.2 Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover WordPress pluginBooking for Appointments and Events Calendar
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.
-
CVE-2026-85132 MEDIUM 4.3 WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan WordPress pluginWPLP Cookie Consent
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.
-
CVE-2026-82848 MEDIUM 5.3 Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure WordPress pluginMasteriyo LMS
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.
-
CVE-2026-84221 MEDIUM 6.8 Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID WordPress pluginKirki
The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.
-
CVE-2026-15386 MEDIUM 5.4 Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text WordPress pluginMeow Gallery
The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.
This page is generated automatically from the CVE Program record cache and reflects the CVE records as of 12 September 2026. The underlying data is also available as JSON.