Critical Vulnerability in Masteriyo LMS WordPress Plugin Allows Unauthenticated Session Termination (CVE-2026-13332)
A critical vulnerability (CVE-2026-13332, CVSS 9.1) exists in the Masteriyo LMS WordPress plugin prior to version 2.3.1. This flaw allows unauthenticated attackers to terminate the active sessions of any user, including administrators, via an unauthenticated AJAX action. Immediate patching is recommended to prevent potential exploitation.