CVE-2026-14184
Description
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | Academy LMS | — | 0 < 3.8.1 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-639 Authorization Bypass Through User-Controlled Key |