← WordPress Vulnerabilities
WordPress security by component

Academy LMS

Academy LMS is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.8.

Plugin slug: academy-lms

CVE-2026-16563: Academy LMS students can read paid and unpublished lessons

Academy LMS before 3.8.3 returns a requested lesson through its single-lesson REST API without verifying course enrollment or the lesson's publication status. Any user who can create a self-service student account, equivalent to Subscriber access, can request arbitrary lessons and disclose paid-course material plus draft, pending and private lessons. The CNA record does not disclose the route, lesson identifier or callback.

PublishedAug 03, 2026
Known safe version3.8.3
Published vulnerabilities for academy-lms
Safe version
Aug 03, 2026 CVE-2026-16563
Academy LMS students can read paid and unpublished lessons
Academy LMS before 3.8.3 returns a requested lesson through its single-lesson REST API without verifying course enrollment or the lesson's publication status. Any user who can create a self-service student account, equivalent to Subscriber access, can request arbitrary lessons and disclose paid-course material plus draft, pending and private lessons. The CNA record does not disclose the route, lesson identifier or callback.
3.8.3
CVE6.5
NVDPending
Jul 31, 2026 CVE-2026-12376
Academy LMS exposes every learner's quiz attempts to enrolled Subscribers
Academy LMS through 3.8.2 does not restrict quiz-attempt records to their owner. Any authenticated Subscriber-or-higher user enrolled in at least one course can request and read quiz attempts belonging to every user across the site, including IP addresses, names, registration dates and quiz results. The published record does not identify the request route or action, attempt or user parameters, authorization callback or record-loading function.
See mitigation notes
CVE4.3
NVDPending
Jul 21, 2026 CVE-2026-14184
Academy LMS: Broken access control
Academy LMS is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is < 3.8.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
3.8.1
CVE5.4
NVDPending
Mar 13, 2024 CVE-2024-1505
Academy LMS – eLearning and online course solution for: Privilege escalation or authentication bypass
Academy LMS – eLearning and online course solution for is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending