CVE-2026-13332
A flaw in the Masteriyo LMS WordPress plugin allows unauthorized users to trigger a function that clears user sessions. This can be used to force any user, including administrators, to be logged out of the website.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running the Masteriyo LMS WordPress plugin on versions prior to 2.3.1.
Real-world impact
An attacker could disrupt site administration and user activity by repeatedly forcing users to log out, effectively locking them out of their active sessions.
Why this severity
This vulnerability is rated critical because it can be exploited remotely over the internet without any user interaction or login credentials, allowing an attacker to disrupt the site's availability for all users.
What to do about it
- 01Upgrade the Masteriyo LMS WordPress plugin to version 2.3.1 or later.
NVD-referenced vendor advisory
Timeline
- Jul 27, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.