All verified exploits

CVE-2026-4484 Privilege Escalation via LMS Instructor API

Deterministic critical WordPress Added cve-verified-cve-2026-4484

Detects Masteriyo LMS plugin versions 2.1.6 and below where the Instructors REST API endpoint accepts a roles parameter without authorization checks. Any authenticated student can escalate to WordPress administrator with a single API request. Update to Masteriyo LMS 2.1.7 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-4484?

Scan your domain free