logo

CVE-2026-13332: Masteriyo LMS Allows Unauthenticated Force-Logout of Any User

ID: 395c697f-d48b-596d-b817-331f4017fb1d

STIX ID: report--395c697f-d48b-596d-b817-331f4017fb1d

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

...
...

A critical vulnerability (CVE-2026-13332, CVSS 9.1) in Masteriyo LMS (< 2.3.1) exposes an unauthenticated AJAX action that can forcibly terminate sessions for any user by ID, enabling admin lockouts and denial-of-service against authenticated users; the report provides technical details, exploitation steps against wp-admin/admin-ajax.php, detection indicators, and remediation guidance (update to 2.3.1, deactivate plugin or block the AJAX action if immediate patching is not possible).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.