Impact
The vulnerability allows an attacker who does not have any existing credentials to register on a WordPress site that has the Academy LMS Pro plugin installed. Because the Social Login addon does not verify that the caller is authorized to choose a role, the attacker can set their role to Administrator during registration. This results in full administrative control over the site, allowing modification of content, themes, plugins, and potentially access to user data. The weakness is a missing role validation flaw (CWE‑269), leading to privileged account creation.
Affected Systems
Any WordPress site that uses the Academy LMS Pro plugin up to and including version 3.3.7 is affected. The vulnerability is present on all supported versions before 3.3.8, regardless of the specific WordPress core release.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity and the EPSS score of less than 1% suggests low overall exploitation probability but still possible. The attack vector is web-based and requires only unauthenticated access to the site's registration endpoint; no additional network privileges are needed. Because the plugin can be installed on any WordPress site, the vulnerability is potentially widespread, but it is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment