S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 25, 2025

CVE-2024-33939 Scanner

CVE-2024-33939 Scanner - Insecure Direct Object Reference vulnerability in Masteriyo LMS

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-33939
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.3.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Masteriyo - LMSby masteriyo
0
Updated Sep 10, 2026View on NVD →
Detail

The Masteriyo LMS is an educational software plugin used by WordPress websites. It is implemented by educators to manage courses, track progress, and provide learning content to students. The software facilitates online learning and academic administration, often used by educational institutions and private educators to enhance the online learning experience. As a learning management system, it is equipped with features to integrate with other educational technologies to streamline the learning process. The robust set of tools and features aids in course creation, student enrollment, and performance monitoring. It aims to support teachers and administrators in providing an organized, engaging learning environment.

The vulnerability identified in the Masteriyo LMS plugin is an Insecure Direct Object Reference (IDOR), which can lead to unauthorized access to user data. This vulnerability allows attackers to bypass authentication controls and access or modify data they shouldn't be able to. IDOR is a common vulnerability in web applications where user input is directly used to access resources without proper authorization checks. Exploiting this vulnerability can lead to exposure of sensitive information or unauthorized changes to data. It highlights the importance of implementing strict access control checks on all endpoints that interact with user data. By exploiting this IDOR, malicious actors can potentially access sensitive course data.

The technical details of this vulnerability involve unprotected API endpoints that allow for unauthorized access to course progress and user learning data. The specific endpoint affected is the '/wp-json/masteriyo/v1/course-progress' API. Without proper authorization, the endpoints can be accessed using crafted requests with altered user IDs, allowing attackers to view and manipulate data. The payloads involve manipulating the 'user_id' parameter in the API request. The exploitation technique involves sending unauthenticated HTTP requests with incremental or specific user IDs to enumerate and access data. This lack of security around user access for sensitive operations poses a significant risk for educational data confidentiality.

If exploited, this vulnerability can lead to several dire consequences. Sensitive user information regarding course progress and status could be exposed, affecting data privacy and integrity. Attackers may gain insights into private learning data without consent. Educational institutions relying on this plugin might face reputational damage and potential legal issues due to compromised information. The exploit can lead to a breach of trust from users concerning data confidentiality. Moreover, unchecked, it can create opportunities for further attacks on the infrastructure using revealed insights.

REFERENCES

Solution Advice
  • Update the Masteriyo LMS plugin to the latest version.
  • Implement strict access control measures on all API endpoints.
  • Ensure proper authentication and authorization checks are enforced.
  • Conduct regular security audits to identify and rectify such vulnerabilities.
  • Educate developers about secure coding practices to prevent IDOR vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.