top of page
perceptive_background_267k.jpg

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing…

Published:

27 juli 2026 om 00:00:00

Alert date:

27 juli 2026 om 23:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A vulnerability in the Masteriyo LMS WordPress plugin before version 2.3.1 allows unauthenticated attackers to force-logout any user on the site, including administrators. The flaw exists in an unauthenticated AJAX action used to clear user sessions, where authorization is not correctly verified. No authentication is required to exploit this vulnerability. Attackers can terminate active sessions for any account, potentially disrupting site administration and user access. This represents a significant authorization bypass issue affecting WordPress sites running the affected plugin versions.

Technical details

Mitigation steps:

Affected products:

Masteriyo LMS WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page