Back to overview

CVE-2026-14184

Description
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.

Metadata

CVE ID
CVE-2026-14184
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-30 08:11 UTC
Published
2026-07-21 06:00 UTC
Last updated
2026-07-21 06:00 UTC
Vendor / Product
Unknown / Academy LMS
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Academy LMS 0 < 3.8.1
Weakness (CWE)
CWESourceDescription
cna CWE-639 Authorization Bypass Through User-Controlled Key
Back to overview