Description
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.
Published: 2025-10-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an attacker who does not have any existing credentials to register on a WordPress site that has the Academy LMS Pro plugin installed. Because the Social Login addon does not verify that the caller is authorized to choose a role, the attacker can set their role to Administrator during registration. This results in full administrative control over the site, allowing modification of content, themes, plugins, and potentially access to user data. The weakness is a missing role validation flaw (CWE‑269), leading to privileged account creation.

Affected Systems

Any WordPress site that uses the Academy LMS Pro plugin up to and including version 3.3.7 is affected. The vulnerability is present on all supported versions before 3.3.8, regardless of the specific WordPress core release.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity and the EPSS score of less than 1% suggests low overall exploitation probability but still possible. The attack vector is web-based and requires only unauthenticated access to the site's registration endpoint; no additional network privileges are needed. Because the plugin can be installed on any WordPress site, the vulnerability is potentially widespread, but it is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on April 22, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Academy LMS Pro to version 3.3.8 or later, which includes role validation during user registration.
  • If an upgrade is not immediately possible, disable or uninstall the Social Login addon to prevent unauthenticated role assignment.
  • Implement a review of role assignment logic in any custom code and enforce strict authorization checks to ensure only authorized users can acquire administrator privileges.

Generated by OpenCVE AI on April 22, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Academylms
Academylms academy Lms Pro
Wordpress
Wordpress wordpress
Vendors & Products Academylms
Academylms academy Lms Pro
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.
Title Academy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login Addon
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Academylms Academy Lms Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:35:39.003Z

Reserved: 2025-09-26T18:36:19.026Z

Link: CVE-2025-11086

cve-icon Vulnrichment

Updated: 2025-10-22T13:29:59.779Z

cve-icon NVD

Status : Deferred

Published: 2025-10-22T12:15:33.427

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-11086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T22:00:18Z

Weaknesses