PT-2026-109359 · Kodezen · Academy Lms – Ai Course Builder

·

CVE-2026-104022

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the add child() function calling add role('academy student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP Error. This makes it possible for authenticated attackers with the academy guardian role or higher to elevate any existing WordPress account — including their own — to the academy student role, gaining edit posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add role() call has already executed and is never reversed, the academy student role grant on their own account persists permanently.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104022

Affected Products

Academy Lms – Ai Course Builder