Impact
The Academy LMS plugin for WordPress contains an error in its delete_lesson_comment AJAX handler: the code that verifies the user’s authorization does not check that the instructor belongs to the target course. As a result, any authenticated user with the instructor role in at least one course can provide a custom course_id while supplying a comment_id from a different course, causing the server to delete that comment and any replies. This flaw allows an attacker to remove lesson comments authored by any user, including administrators, which undermines data integrity and can damage the learning experience.
Affected Systems
All installations of the Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin version 4.0.3 and earlier, regardless of the underlying WordPress theme or host environment. The vulnerability exists in the plugin’s core PHP code and its AJAX interface.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity. No EPSS score is available and it is not listed in CISA’s KEV catalog. Exploitation requires that the attacker be logged in as a user who has the instructor role for at least one course; no additional privileges or remote code execution are needed. Once authenticated, the attacker can supply arbitrary course identifiers to bypass instructor checks and delete arbitrary comments across all courses, making the flaw highly actionable for malicious users with legitimate instructor accounts.
OpenCVE Enrichment