CVE-2026-14184 PUBLISHED

Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR

Assigner: WPScan
Reserved: 30.06.2026 Published: 21.07.2026 Updated: 21.07.2026

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.

Product Status

Vendor Unknown
Product Academy LMS
Versions Default: unaffected
  • affected from 0 to 3.8.1 (excl.)

Credits

  • Mustafa Ahmed finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE