WordPress security by component
Academy LMS
Plugin description
Academy LMS is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
academy-lmsLatest vulnerability
CVE-2026-16563: Academy LMS students can read paid and unpublished lessons
Academy LMS before 3.8.3 returns a requested lesson through its single-lesson REST API without verifying course enrollment or the lesson's publication status. Any user who can create a self-service student account, equivalent to Subscriber access, can request arbitrary lessons and disclose paid-course material plus draft, pending and private lessons. The CNA record does not disclose the route, lesson identifier or callback.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16563
Academy LMS students can read paid and unpublished lessons
Academy LMS before 3.8.3 returns a requested lesson through its single-lesson REST API without verifying course enrollment or the lesson's publication status. Any user who can create a self-service student account, equivalent to Subscriber access, can request arbitrary lessons and disclose paid-course material plus draft, pending and private lessons. The CNA record does not disclose the route, lesson identifier or callback.
|
3.8.3 |
CVE6.5
NVDPending
|
| Jul 31, 2026 |
CVE-2026-12376
Academy LMS exposes every learner's quiz attempts to enrolled Subscribers
Academy LMS through 3.8.2 does not restrict quiz-attempt records to their owner. Any authenticated Subscriber-or-higher user enrolled in at least one course can request and read quiz attempts belonging to every user across the site, including IP addresses, names, registration dates and quiz results. The published record does not identify the request route or action, attempt or user parameters, authorization callback or record-loading function.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 21, 2026 |
CVE-2026-14184
Academy LMS: Broken access control
Academy LMS is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is < 3.8.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
3.8.1 |
CVE5.4
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1505
Academy LMS – eLearning and online course solution for: Privilege escalation or authentication bypass
Academy LMS – eLearning and online course solution for is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|