


Perceptive Security
SOC/SIEM Consultancy

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing…
Published:
26 juli 2026 om 22:00:00
Alert date:
27 juli 2026 om 21:04:07
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A vulnerability in the Masteriyo LMS WordPress plugin before version 2.3.1 allows unauthenticated attackers to force-logout any user on the site, including administrators. The flaw exists in an unauthenticated AJAX action used to clear user sessions, where authorization is not correctly verified. No authentication is required to exploit this vulnerability. Attackers can terminate active sessions for any account, potentially disrupting site administration and user access. This represents a significant authorization bypass issue affecting WordPress sites running the affected plugin versions.
Technical details
Mitigation steps:
Affected products:
Masteriyo LMS WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-13332
https://wpscan.com/vulnerability/f987c823-f215-48f6-86fe-8d898f2c2d94/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
