๐Ÿ” CVE Alert

CVE-2026-16563

UNKNOWN 0.0

Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.

Vendor unknown
Product academy lms
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for unknown academy lms

Be the first to know when new unknown vulnerabilities affecting unknown academy lms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Academy LMS
0 < 3.8.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/eec480b0-67af-4642-b6b3-cba095394286/

Credits

Pedro Pinho WPScan