CVE-2026-12376
Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results.
| Vendor | unknown |
| Product | academy lms |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown academy lms
Be the first to know when new unknown vulnerabilities affecting unknown academy lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Academy LMS
0 โค 3.8.2
References
Credits
Stefan Spasic WPScan