๐Ÿ” CVE Alert

CVE-2026-104049

UNKNOWN 0.0

Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in.

Vendor unknown
Product academy lms
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown academy lms

Be the first to know when new unknown vulnerabilities affecting unknown academy lms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Academy LMS
0 < 4.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/277f48d0-c5e8-4790-ada6-51050d308217/

Credits

Morato Antoine WPScan