PT-2026-66685 · WordPress · Academy Lms
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Academy LMS WordPress plugin versions prior to 3.8.3
Description
An improper access control issue allows any authenticated user with subscriber-level access or higher who is enrolled in at least one course to access quiz attempt records belonging to other users. This allows the unauthorized reading of personal data across the entire site, including names, IP addresses, registration dates, and quiz results.
Recommendations
Update Academy LMS WordPress plugin to version 3.8.3 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Academy Lms