The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the add_child() function calling add_role('academy_student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP_Error. This makes it possible for authenticated attackers with the academy_guardian role or higher to elevate any existing WordPress account — including their own — to the academy_student role, gaining edit_posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload_files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email_exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add_role() call has already executed and is never reversed, the academy_student role grant on their own account persists permanently.