Impact
The Academy LMS WordPress plugin version 4.0.0 and earlier fails to verify that a user is enrolled in a course or owns the lesson before sending lesson content via its REST API. This omission allows any user with a self‑registerable student account to read the full text of arbitrary lessons, even those from paid or private courses they are not enrolled in. The vulnerability leads to direct leakage of protected educational material and undermines the confidentiality that the plugin is meant to provide.
Affected Systems
The affected product is the Academy LMS WordPress plugin, versions earlier than 4.0.0. Any installation of these versions is susceptible to the vulnerability, allowing authorized self‑registered student accounts to access lesson content without proper enrollment or ownership verification.
Risk and Exploitability
The flaw can be exploited by any user who can register a student account. The attacker can issue requests to the topic REST endpoint and retrieve full lesson content without enrollment checks. This results in confidentiality exposure of paid or private course material. While the CVSS metric is not available, the lack of access controls is a high‑risk flaw. EPSS data is unavailable and the vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment