Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-08-03

CVE-2026-16563 - Academy Lms Plugin

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.

PLUGIN Academy Lms

CVE-2026-16563

MEDIUM CVSS 6.5 2026-08-03
Threat Entry Updated 2026-07-31

CVE-2026-12376 - Academy Lms Plugin

The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results.

PLUGIN Academy Lms

CVE-2026-12376

MEDIUM CVSS 4.3 2026-07-31
Threat Entry Updated 2026-07-21

CVE-2026-14184 - Academy Lms Plugin

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.

PLUGIN Academy Lms

CVE-2026-14184

MEDIUM CVSS 5.4 2026-07-21
Threat Entry Updated 2025-01-22

CVE-2024-1505 - Academy Lms Plugin

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated attackers, with minimal permissions such as students, to elevate their user role to that of an administrator.

PLUGIN Academy Lms

CVE-2024-1505

HIGH CVSS 8.8 2024-03-13
Scroll to top