Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS Academy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Academy LMS: from n/a through 3.3.4.
Metrics
Affected Vendors & Products
Fixes
Solution
Update the WordPress Academy LMS plugin to the latest available version (at least 3.3.5).
Workaround
No workaround given by the vendor.
References
History
Mon, 22 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS Academy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Academy LMS: from n/a through 3.3.4. | |
Title | WordPress Academy LMS Plugin <= 3.3.4 - Insecure Direct Object References (IDOR) Vulnerability | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-22T18:26:02.167Z
Reserved: 2025-09-17T18:00:53.704Z
Link: CVE-2025-59562

No data.

Status : Received
Published: 2025-09-22T19:16:24.490
Modified: 2025-09-22T19:16:24.490
Link: CVE-2025-59562

No data.

No data.