PT-2026-109359 · Kodezen · Academy Lms – Ai Course Builder

·

CVE-2026-104022

·

Publicado

2026-10-10

·

Atualizado

2026-10-10

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the add child() function calling add role('academy student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP Error. This makes it possible for authenticated attackers with the academy guardian role or higher to elevate any existing WordPress account — including their own — to the academy student role, gaining edit posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add role() call has already executed and is never reversed, the academy student role grant on their own account persists permanently.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-104022

Produtos afetados

Academy Lms – Ai Course Builder