The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 22 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Oct 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site. | |
| Title | Academy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login Addon | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-10-22T13:30:11.884Z
Reserved: 2025-09-26T18:36:19.026Z
Link: CVE-2025-11086
Updated: 2025-10-22T13:29:59.779Z
Status : Awaiting Analysis
Published: 2025-10-22T12:15:33.427
Modified: 2025-10-22T21:12:48.953
Link: CVE-2025-11086
No data.
OpenCVE Enrichment
No data.