[
  {
    "id": "CVE-2026-82851",
    "title": "Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR",
    "description": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.",
    "published": "2026-09-12T06:00:10.305Z",
    "updated": "2026-09-12T15:32:39.491Z",
    "assigner": "WPScan",
    "product": "Masteriyo LMS",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Masteriyo LMS",
        "versions": [
          "1.14.0 – < 3.4.1"
        ]
      }
    ],
    "cwe": [
      "CWE-639"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 2.7,
      "baseSeverity": "LOW",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"
    },
    "references": [
      "https://wpscan.com/vulnerability/07664081-72c3-4f7e-9324-e0047b6e6d22/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-82851"
  },
  {
    "id": "CVE-2026-82847",
    "title": "Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights",
    "description": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.",
    "published": "2026-09-12T06:00:10.131Z",
    "updated": "2026-09-12T15:32:53.903Z",
    "assigner": "WPScan",
    "product": "Masteriyo LMS",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Masteriyo LMS",
        "versions": [
          "< 3.4.1"
        ]
      }
    ],
    "cwe": [
      "CWE-79"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 6.8,
      "baseSeverity": "MEDIUM",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
    },
    "references": [
      "https://wpscan.com/vulnerability/9cc4f7a7-e5b9-48fe-962b-f5d0753e6158/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-82847"
  },
  {
    "id": "CVE-2026-82845",
    "title": "Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection",
    "description": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS  WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.",
    "published": "2026-09-12T06:00:09.956Z",
    "updated": "2026-09-12T15:33:08.896Z",
    "assigner": "WPScan",
    "product": "Masteriyo LMS",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Masteriyo LMS",
        "versions": [
          "< 3.4.1"
        ]
      }
    ],
    "cwe": [
      "CWE-502"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 9.9,
      "baseSeverity": "CRITICAL",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
    },
    "references": [
      "https://wpscan.com/vulnerability/5ced30ea-8b78-495f-b10c-42b3f10adcb3/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-82845"
  },
  {
    "id": "CVE-2026-77705",
    "title": "Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover",
    "description": "The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.",
    "published": "2026-09-12T06:00:07.938Z",
    "updated": "2026-09-12T15:35:37.592Z",
    "assigner": "WPScan",
    "product": "Booking for Appointments and Events Calendar",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Booking for Appointments and Events Calendar",
        "versions": [
          "< 2.4.10"
        ]
      }
    ],
    "cwe": [
      "CWE-639"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 7.2,
      "baseSeverity": "HIGH",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
    },
    "references": [
      "https://wpscan.com/vulnerability/bfd0ce74-f91e-41fe-8288-7b1d34dd16fe/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-77705"
  },
  {
    "id": "CVE-2026-85132",
    "title": "WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan",
    "description": "The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.",
    "published": "2026-09-09T06:00:08.871Z",
    "updated": "2026-09-09T15:29:47.746Z",
    "assigner": "WPScan",
    "product": "WPLP Cookie Consent",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "WPLP Cookie Consent",
        "versions": [
          "4.0.2 – < 4.4.2"
        ]
      }
    ],
    "cwe": [
      "CWE-862"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 4.3,
      "baseSeverity": "MEDIUM",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
    },
    "references": [
      "https://wpscan.com/vulnerability/412f604b-ee33-42b6-8a39-00f7564d4e2b/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-85132"
  },
  {
    "id": "CVE-2026-82848",
    "title": "Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure",
    "description": "The Masteriyo LMS  WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.",
    "published": "2026-09-09T06:00:07.288Z",
    "updated": "2026-09-09T15:37:54.624Z",
    "assigner": "WPScan",
    "product": "Masteriyo LMS",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Masteriyo LMS",
        "versions": [
          "1.3.1 – < 3.4.0"
        ]
      }
    ],
    "cwe": [
      "CWE-862"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 5.3,
      "baseSeverity": "MEDIUM",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
    },
    "references": [
      "https://wpscan.com/vulnerability/a6e580be-ce42-479d-97cd-fcfa2f752b2c/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-82848"
  },
  {
    "id": "CVE-2026-84221",
    "title": "Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID",
    "description": "The Kirki  WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.",
    "published": "2026-09-05T06:00:08.170Z",
    "updated": "2026-09-06T10:37:53.220Z",
    "assigner": "WPScan",
    "product": "Kirki",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Kirki",
        "versions": [
          "6.0.0 – < 6.3.0"
        ]
      }
    ],
    "cwe": [
      "CWE-89"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 6.8,
      "baseSeverity": "MEDIUM",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"
    },
    "references": [
      "https://wpscan.com/vulnerability/6c34da62-46fb-4dd4-a433-bd3df4d9fcfd/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-84221"
  },
  {
    "id": "CVE-2026-15386",
    "title": "Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text",
    "description": "The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators) who views a post containing such a gallery.",
    "published": "2026-08-07T06:00:12.872Z",
    "updated": "2026-08-07T18:09:25.060Z",
    "assigner": "WPScan",
    "product": "Meow Gallery",
    "isWordPress": true,
    "pluginSlug": "",
    "affected": [
      {
        "vendor": "",
        "product": "Meow Gallery",
        "versions": [
          "< 5.5.2"
        ]
      }
    ],
    "cwe": [
      "CWE-79"
    ],
    "cvss": {
      "version": "3.1",
      "baseScore": 5.4,
      "baseSeverity": "MEDIUM",
      "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
    },
    "references": [
      "https://wpscan.com/vulnerability/f76518ec-3abb-4b3c-b592-f5e24059304b/"
    ],
    "url": "https://www.cve.org/CVERecord?id=CVE-2026-15386"
  }
]
