๐Ÿ” CVE Alert

CVE-2026-14184

UNKNOWN 0.0

Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.

Vendor unknown
Product academy lms
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for unknown academy lms

Be the first to know when new unknown vulnerabilities affecting unknown academy lms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Academy LMS
0 < 3.8.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/56a5b91b-1e1a-429d-b9e9-a1a107183124/

Credits

Mustafa Ahmed WPScan