CyberRota Analysis
AI-GeneratedThe Masteriyo LMS plugin for WordPress prior to version 3.4.0 is vulnerable due to a lack of authorization checks in its REST API, enabling unauthenticated users to access sensitive course enrollment records, including learner status and progress data. Additionally, enrolled users can exploit this vulnerability to view other learners' enrollment details. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.
Original NVD Description
The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well.