6.5
CVE-2026-104915
- EPSS 0.23%
- Veröffentlicht 10.10.2026 02:26:30
- Zuletzt bearbeitet 10.10.2026 03:17:04
- Erkennungen
Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id
Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct. This is exploitable by any user registered as an Academy instructor for at least one course, as they can supply their own course_id to pass the instructor check while targeting comments belonging to entirely different courses.
Mögliche Gegenmaßnahme
Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning: Update to version 4.0.4, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerkodezen
≫
Produkt
Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
Default Statusunaffected
Version <=
4.0.3
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
Version
*-4.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.128 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://plugins.trac.wordpress.org/changeset?reponame=&old=3734598%40academy&new=3734598%40academy
https://www.wordfence.com/threat-intel/vulnerabilities/id/2640d1f8-958d-4556-919c-58df5bf15b40?source=cve
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L496
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L477
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L480
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L469
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/classes/abstract-ajax-handler.php#L43
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/traits/courses.php#L380
https://www.wordfence.com/threat-intel/vulnerabilities/id/2640d1f8-958d-4556-919c-58df5bf15b40