Description
The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Confidentiality Disclosure
Action: Immediate Update
AI Analysis

Impact

The Academy LMS WordPress plugin version 4.0.0 and earlier fails to verify that a user is enrolled in a course or owns the lesson before sending lesson content via its REST API. This omission allows any user with a self‑registerable student account to read the full text of arbitrary lessons, even those from paid or private courses they are not enrolled in. The vulnerability leads to direct leakage of protected educational material and undermines the confidentiality that the plugin is meant to provide.

Affected Systems

The affected product is the Academy LMS WordPress plugin, versions earlier than 4.0.0. Any installation of these versions is susceptible to the vulnerability, allowing authorized self‑registered student accounts to access lesson content without proper enrollment or ownership verification.

Risk and Exploitability

The flaw can be exploited by any user who can register a student account. The attacker can issue requests to the topic REST endpoint and retrieve full lesson content without enrollment checks. This results in confidentiality exposure of paid or private course material. While the CVSS metric is not available, the lack of access controls is a high‑risk flaw. EPSS data is unavailable and the vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on October 7, 2026 at 08:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Academy LMS plugin to version 4.0.0 or later, which restores proper enrollment checks before lesson content is returned.
  • If an upgrade cannot be performed immediately, modify the REST API handling (e.g., by adding a filter or hook) so that the lesson endpoint verifies the current user’s enrollment status or membership level before outputting content.
  • Block or restrict unauthenticated access to the lesson REST endpoint by enforcing authentication or rate limiting, and monitor access logs for anomalous request patterns to the lesson route.

Generated by OpenCVE AI on October 7, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in.
Title Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:04.901Z

Reserved: 2026-10-01T17:31:45.712Z

Link: CVE-2026-104049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.657

Modified: 2026-10-07T07:16:57.657

Link: CVE-2026-104049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:15:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control