CVE-2026-4484Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (7 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for authenticated attackers, with Student-level access and above, to elevate their privileges to that of an administrator.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • 7 total mentions across 1 day

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-03-26: 7PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-26: 2Technical Details · 2026-03-26: 603-26
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets6 URLs
Full discourse7 posts
  • Nxploited@Nxploited
    Disclosure

    Plugin: Masteriyo LMS Version: ≤ 2.1.6 CVE: CVE-2026-4484 CVSS Score: 9.8 (Critical) 🔗 Telegram Channel: https://t.me/KNxploited #CyberSecurity #WordPress #Vulnerability #Exploit #PrivilegeEscalation #LMS #Infosec #BugBounty #SecurityResearch https://t.co/Ulb3RLfqJe

    Post summary

    The post announces a critical vulnerability (CVE-2026-4484) in Masteriyo LMS for WordPress, detailing the affected versions and a high CVSS score, but does not provide exploitation details or patches.

    00010177
    94 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4484 — CVSS 9.8/10 ██████████ The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/fqwYsJYV8h

    Post summary

    CVE-2026-4484 is a critical privilege‑escalation vulnerability in the Masteriyo LMS WordPress plugin, with a patch now available.

    1000046
    10 followersView on X
  • Fernando Karl@fernandokarl
    Disclosure

    🚨 New CVE-2026-4484 alert! This could impact your network security. Ensure your systems are patched and stay informed to safeguard sensitive data. How are you enhancing your defenses? Let’s discuss strategies! 🔒 #CyberSecurity #CVE #InfoSec https://www.tenable.com/cve/CVE-2026-4484

    Post summary

    An alert announces the recently disclosed CVE-2026-4484, urging users to patch systems and stay informed, but it provides no technical or exploit details.

    0000050
    258 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4484 The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to u… https://www.cve.org/CVERecord?id=CVE-2026-4484

    Post summary

    The post announces CVE-2026-4484, a privilege escalation flaw in Masteriyo LMS plugin versions up to 2.1.6; it makes no mention of PoCs, exploits, active use, or available patches.

    00000112
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4484 - Critical The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role ... https://www.thehackerwire.com/vulnerability/CVE-2026-4484/ https://t.co/Cr1MJUajfW

    Post summary

    The post announces CVE-2026-4484, a privilege‑escalation vulnerability in the Masteriyo LMS plugin up to version 2.1.6, providing technical detail but no PoC, exploit, or patch information.

    0000047
    148 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4484: CRITICAL] WordPress Masteriyo LMS plugin (up to v2.1.6) has a Privilege Escalation vulnerability. Attackers can elevate their role from Student to Admin. #CyberSecurity#cve,CVE-2026-4484,#cybersecurity https://cvefind.com/CVE-2026-4484

    Post summary

    This notice announces that the WordPress Masteriyo LMS plugin up to version 2.1.6 contains a critical privilege‑escalation flaw allowing attackers to elevate from Student to Admin.

    0000049
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4484: Masteriyo LMS <= 2.1.6 - Missing ... Student to admin in one API call - `InstructorsController::prepare_object_for_database` lets any authenticated user rewr... https://zerodaysignal.com/vulnerability/CVE-2026-4484 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑4484, detailing that authenticated users in Masteriyo LMS 2.1.6 can elevate privileges via a single API call, and links to additional information on zerodaysignal.com.

    0000064
    169 followersView on X

Explore more