8

CVE-2026-39598

WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability

Academy LMS Pro < 3.5.2 - Authenticated (Custom+) Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server.

This issue affects Academy LMS Pro: from n/a before 3.5.2.
Mögliche Gegenmaßnahme
Academy LMS Pro: Update to version 3.5.2, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerKodezen LLC
Produkt Academy LMS Pro
Default Statusunaffected
Version n/a
Version < 3.5.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Academy LMS Pro
Version [*, 3.5.2)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.125
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
21595511-bba5-4825-b968-b78d1f9984a3 8 0 0
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://patchstack.com/database/wordpress/plugin/academy-pro/vulnerability/wordpress-academy-lms-pro-plugin-3-5-2-arbitrary-file-upload-vulnerability?_s_id=cve
vdb-entry
https://www.wordfence.com/threat-intel/vulnerabilities/id/3cc4a11a-7562-44e7-ac8e-770c4e39e2c7
Third Party Advisory