CVE-2026-65463

WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerability

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.


We have discovered 201 live websites that are affected by CVE-2026-65463.

Run a Free Instant Scan




Affected Software

Product  Masteriyo LMS
Category Wordpress Plugins
Vulnerable Domains201 live websites (100% of Masteriyo LMS install base)
Vulnerable Versions
  • from 0 through 2.3.1
Vulnerable Versions Count29 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Celvex Group | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-65463
United States43 websites



GB16 websites
Germany15 websites
Cyprus12 websites
Russia8 websites
France7 websites
Brazil7 websites
Italy7 websites
Chile6 websites
South Africa6 websites

Website Distribution by TLD

Number of websites using CVE-2026-65463
.com86 websites
.org8 websites
.co.uk7 websites
.net6 websites
.it6 websites
.com.br6 websites
.ru6 websites
.fr5 websites
.pl5 websites
.com.au4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65463

Top websites that are affected by CVE-2026-65463. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.com Romania***,***
******************.ca Canada***,***
****.**.uk GB*,***,***
******.fi Finland*,***,***
***********.cz Czech Republic*,***,***
*******.com GB*,***,***
*******.com United States*,***,***
*******.com United States*,***,***
***.************.com GB*,***,***
*********.be Belgium*,***,***
See full domain list

FAQ

CVE-2026-65463 is Authorization Bypass Through User-Controlled Key in Masteriyo LMS
A total of 201 websites have been identified as vulnerable to CVE-2026-65463, based on global website indexing conducted by WebTechSurvey.
The Masteriyo LMS is affected by the CVE-2026-65463 vulnerability.
Masteriyo LMS versions up to and including 2.3.1 are vulnerable to CVE-2026-65463.