PT-2026-109359 · Kodezen · Academy Lms – Ai Course Builder
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the
add child() function calling add role('academy student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP Error. This makes it possible for authenticated attackers with the academy guardian role or higher to elevate any existing WordPress account — including their own — to the academy student role, gaining edit posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add role() call has already executed and is never reversed, the academy student role grant on their own account persists permanently.Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Academy Lms – Ai Course Builder