6.5

CVE-2026-104915

Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id

Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id

The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct. This is exploitable by any user registered as an Academy instructor for at least one course, as they can supply their own course_id to pass the instructor check while targeting comments belonging to entirely different courses.
Mögliche Gegenmaßnahme
Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning: Update to version 4.0.4, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerkodezen
≫
Produkt Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
Default Statusunaffected
Version <= 4.0.3
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
Version *-4.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://plugins.trac.wordpress.org/changeset?reponame=&old=3734598%40academy&new=3734598%40academy
https://www.wordfence.com/threat-intel/vulnerabilities/id/2640d1f8-958d-4556-919c-58df5bf15b40?source=cve
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L496
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L477
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L480
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php#L469
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/classes/abstract-ajax-handler.php#L43
https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/traits/courses.php#L380
https://www.wordfence.com/threat-intel/vulnerabilities/id/2640d1f8-958d-4556-919c-58df5bf15b40
Third Party Advisory