CVE-2026-10824 | Masteriyo LMS Plugin up to 2.2.0 on WordPress course-progress REST API access control (EUVD-2026-39186)
A vulnerability was found in Masteriyo LMS Plugin up to 2.2.0 on WordPress. It has been classified as critical. Affected by this issue is some unknown functionality of the component course-progress REST API. This manipulation causes improper access controls.
This vulnerability appears as CVE-2026-10824. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.