Detects Masteriyo LMS plugin versions 2.1.6 and below where the Instructors REST API endpoint accepts a roles parameter without authorization checks. Any authenticated student can escalate to WordPress administrator with a single API request. Update to Masteriyo LMS 2.1.7 or later.
Is your app exploitable through CVE-2026-4484?
Scan your domain free