Description
The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of quiz answer options across courses
Action: Apply Update
AI Analysis

Impact

The Academy LMS WordPress plugin, when used with a version before 4.0.0, contains a flaw that allows any authenticated user who can view a course’s quiz to retrieve the answer options for quiz questions that belong to courses they are not authorized to access. The plugin fails to verify that a question actually belongs to the course requested by the user before returning the associated answers, potentially exposing quiz solutions to enrolled students or subscribers of other courses.

Affected Systems

This vulnerability affects the Academy LMS plugin for WordPress in all releases prior to version 4.0.0. The vendor is listed as "Unknown:Academy LMS" and no specific patch version is indicated beyond the fact that the flaw is fixed in or after 4.0.0. Users should verify that they are running a version equal to or newer than 4.0.0 to ensure the fix is applied.

Risk and Exploitability

The attack vector requires only an authenticated session with a user who can access at least one course. The attacker can simply request the quiz answer data through the plugin’s rendering endpoint; no external code execution or privilege escalation is needed. The CVSS score of 4.3 indicates a moderate severity impact. Because the EPSS score is not available, no publicly known exploitation, and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain. However, the unintended exposure of correct answers compromises course integrity and student data confidentiality, making the risk moderate to high for organizations that rely on the plugin’s quiz features.

Generated by OpenCVE AI on October 7, 2026 at 11:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Academy LMS plugin to version 4.0.0 or newer
  • Enforce strict role‑based access control so that quiz answer data is only returned to users who are enrolled in the relevant course or have instructor privileges
  • Audit any custom code or hooks that interact with quiz data to ensure that course membership checks are performed before data is exposed

Generated by OpenCVE AI on October 7, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in.
Title Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T10:09:58.070Z

Reserved: 2026-10-01T17:33:06.495Z

Link: CVE-2026-104050

cve-icon Vulnrichment

Updated: 2026-10-07T09:58:49.821Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.760

Modified: 2026-10-07T11:17:10.157

Link: CVE-2026-104050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T12:00:15Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key