Academy LMS <= 3.8.2 - Authenticated (Subscriber+) Information Exposure
medium
The Academy LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 4, 2026
CVE-2026-12376 on NVD →
Academy LMS <= 3.8.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Lesson Content Disclosure
medium
The Academy LMS plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.8.2. This is due to missing enrollment and course-access validation in the lessons REST API get_item() function, which set author_id to null for any user with the academy_student role, allowing unrestricted les...
- CVSS:
- 4.3
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Jul 24, 2026
CVE-2026-16563 on NVD →
Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
medium
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 via the 'save_lesson_note', 'get_lesson_note', and 'complete_lesson_video' AJAX handlers due to missing validation on a user controlle...
- CVSS:
- 4.3
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Jul 13, 2026
CVE-2026-9341 on NVD →
Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure
medium
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to the '/topics' REST API endpoint being registered with a permission callback set to '__return_true', allowing unauthenticat...
- CVSS:
- 5.3
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- Jul 1, 2026
CVE-2026-5348 on NVD →
Academy LMS <= 3.8.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Note/Progress Modification
medium
The Academy LMS plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify other user's notes and progress.
- CVSS:
- 4.3
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Jun 30, 2026
CVE-2026-14184 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] <= 3.5.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.5.3.
- Affected:
- up to 3.5.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25372 on NVD →
Academy LMS <= 3.5.3 - Missing Authorization
medium
The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.5.3. This makes it possible for authenticated attackers, with instructor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.4
- Disclosed:
- Feb 17, 2026
CVE-2026-25372 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 3.5.1
unknown
[en] The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password and relying solely...
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
- Disclosed:
- Jan 21, 2026
CVE-2025-15521 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover
critical
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password and relying solely on a...
- CVSS:
- 9.8
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.1
- Disclosed:
- Jan 20, 2026
CVE-2025-15521 on NVD →
Academy LMS <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Academy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Dec 30, 2025
CVE-2025-68527 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] <= 3.4.0 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC Academy LMS academy allows Stored XSS.This issue affects Academy LMS: from n/a through <= 3.4.0.
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68527 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 3.3.9
unknown
[en] The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.8 via deserialization of untrusted input in the 'import_all_courses' function. This makes it possible for authenticated attackers, with Adminis...
- Affected:
- up to 3.3.9
- Fixed in:
- 3.3.9
- Disclosed:
- Nov 8, 2025
CVE-2025-12099 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses'
high
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.8 via deserialization of untrusted input in the 'import_all_courses' function. This makes it possible for authenticated attackers, with Administrato...
- CVSS:
- 7.2
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- Nov 7, 2025
CVE-2025-12099 on NVD →
Academy LMS <= 3.3.4 - Authenticated (Academy Instructor+) Insecure Direct Object Reference
medium
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Academy Instructor-level...
- CVSS:
- 4.3
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.5
- Disclosed:
- Sep 22, 2025
CVE-2025-59562 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 2.0.5
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jul 22, 2024
CVE-2024-38701 on NVD →
Academy LMS <= 2.0.4 - Missing Authorization
low
The Academy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the quiz_attempts_permissions_check() function in versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with academy instructor-level access and above, to view quiz...
- CVSS:
- 2.7
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Jul 11, 2024
CVE-2024-38701 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 2.0.11
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
- Affected:
- up to 2.0.11
- Fixed in:
- 2.0.11
- Disclosed:
- Jul 6, 2024
CVE-2024-37234 on NVD →
Academy LMS <= 2.0.10 - Open Redirect
high
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.10. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentiall...
- CVSS:
- 8.3
- Affected:
- up to 2.0.10
- Fixed in:
- 2.0.11
- Disclosed:
- Jun 21, 2024
CVE-2024-37234 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 1.9.17
unknown
[en] Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16.
- Affected:
- up to 1.9.17
- Fixed in:
- 1.9.17
- Disclosed:
- Jun 9, 2024
CVE-2024-32714 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 1.9.26
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.
- Affected:
- up to 1.9.26
- Fixed in:
- 1.9.26
- Disclosed:
- May 13, 2024
CVE-2024-35171 on NVD →
Academy LMS <= 1.9.25 - Unauthenticated Sensitive Information Exposure
medium
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.9.25
- Fixed in:
- 1.9.26
- Disclosed:
- May 10, 2024
CVE-2024-35171 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 1.9.17
unknown
[en] Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
- Affected:
- up to 1.9.17
- Fixed in:
- 1.9.17
- Disclosed:
- May 6, 2024
CVE-2024-33912 on NVD →
Academy LMS <= 1.9.16 - Missing Authorization
medium
The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on afunction in versions up to, and including, 1.9.16. This makes it possible for authenticated attackers, with student-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.9.16
- Fixed in:
- 1.9.17
- Disclosed:
- Apr 29, 2024
CVE-2024-33912 on NVD →
Academy LMS <= 1.9.16 - Missing Authorization
medium
The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to insufficient validation on the enroll_course() function in versions up to, and including, 1.9.16. This makes it possible for authenticated attackers, with subscriber-level access and above, to enroll in paid courses for free.
- CVSS:
- 5.4
- Affected:
- up to 1.9.16
- Fixed in:
- 1.9.17
- Disclosed:
- Apr 22, 2024
CVE-2024-32714 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 1.9.20
unknown
[en] The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated a...
- Affected:
- up to 1.9.20
- Fixed in:
- 1.9.20
- Disclosed:
- Mar 13, 2024
CVE-2024-1505 on NVD →
Academy LMS – eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege Escalation
high
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated attack...
- CVSS:
- 8.8
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.20
- Disclosed:
- Feb 21, 2024
CVE-2024-1505 on NVD →
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution [academy] < 3.3.5
unknown
- Affected:
- up to 3.3.5
- Fixed in:
- 3.3.5
CVE-2025-59562 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database