LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-13332

Published
CVSS9.1
Severitycritical
WeaknessCWE-287
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-13332

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-13332.