PT-2026-109359 · Kodezen · Academy Lms – Ai Course Builder
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the
add child() function calling add role('academy student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP Error. This makes it possible for authenticated attackers with the academy guardian role or higher to elevate any existing WordPress account — including their own — to the academy student role, gaining edit posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add role() call has already executed and is never reversed, the academy student role grant on their own account persists permanently.Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Academy Lms – Ai Course Builder