Impact
The Academy LMS WordPress plugin, when used with a version before 4.0.0, contains a flaw that allows any authenticated user who can view a course’s quiz to retrieve the answer options for quiz questions that belong to courses they are not authorized to access. The plugin fails to verify that a question actually belongs to the course requested by the user before returning the associated answers, potentially exposing quiz solutions to enrolled students or subscribers of other courses.
Affected Systems
This vulnerability affects the Academy LMS plugin for WordPress in all releases prior to version 4.0.0. The vendor is listed as "Unknown:Academy LMS" and no specific patch version is indicated beyond the fact that the flaw is fixed in or after 4.0.0. Users should verify that they are running a version equal to or newer than 4.0.0 to ensure the fix is applied.
Risk and Exploitability
The attack vector requires only an authenticated session with a user who can access at least one course. The attacker can simply request the quiz answer data through the plugin’s rendering endpoint; no external code execution or privilege escalation is needed. The CVSS score of 4.3 indicates a moderate severity impact. Because the EPSS score is not available, no publicly known exploitation, and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain. However, the unintended exposure of correct answers compromises course integrity and student data confidentiality, making the risk moderate to high for organizations that rely on the plugin’s quiz features.
OpenCVE Enrichment