CVE-2026-104022 PUBLISHED

Academy LMS <= 4.0.3 - Authenticated (Custom+) Privilege Escalation to add_child REST endpoint

Assigner: Wordfence
Reserved: 01.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the add_child() function calling add_role('academy_student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP_Error. This makes it possible for authenticated attackers with the academy_guardian role or higher to elevate any existing WordPress account — including their own — to the academy_student role, gaining edit_posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload_files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email_exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add_role() call has already executed and is never reversed, the academy_student role grant on their own account persists permanently.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor kodezen
Product Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
Versions Default: unaffected
  • affected from 0 to 4.0.3 (incl.)

Credits

  • Wordfence PRISM finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE