Impact
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution is vulnerable due to the 'enqueue_social_login_script' function, which allows unauthenticated attackers to read sensitive data when Facebook Social Login is enabled. The exposed data includes the Facebook App Secret, a credential that could be leveraged for unauthorized access to the social media integration or to impersonate the site on Facebook. The vulnerability does not require authentication but does rely on the social login script being loaded by a visitor of the site.
Affected Systems
All installations of Academy LMS Pro up to and including version 3.3.8 are affected. The plugin is distributed by the vendor academylms:Academy LMS Pro and is used by WordPress sites implementing an eLearning solution that may enable Facebook social login.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability, and the EPSS score of less than 1% suggests a low likelihood that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely a direct web request to a page that triggers the enqueue_social_login_script function, enabling any visitor to read the exposed App Secret if the social login feature is enabled.
OpenCVE Enrichment