Description
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct. This is exploitable by any user registered as an Academy instructor for at least one course, as they can supply their own course_id to pass the instructor check while targeting comments belonging to entirely different courses.
Published: 2026-10-10
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass Leading to Unauthorized Comment Deletion
Action: Patch Now
AI Analysis

Impact

The Academy LMS plugin for WordPress contains an error in its delete_lesson_comment AJAX handler: the code that verifies the user’s authorization does not check that the instructor belongs to the target course. As a result, any authenticated user with the instructor role in at least one course can provide a custom course_id while supplying a comment_id from a different course, causing the server to delete that comment and any replies. This flaw allows an attacker to remove lesson comments authored by any user, including administrators, which undermines data integrity and can damage the learning experience.

Affected Systems

All installations of the Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin version 4.0.3 and earlier, regardless of the underlying WordPress theme or host environment. The vulnerability exists in the plugin’s core PHP code and its AJAX interface.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating moderate severity. No EPSS score is available and it is not listed in CISA’s KEV catalog. Exploitation requires that the attacker be logged in as a user who has the instructor role for at least one course; no additional privileges or remote code execution are needed. Once authenticated, the attacker can supply arbitrary course identifiers to bypass instructor checks and delete arbitrary comments across all courses, making the flaw highly actionable for malicious users with legitimate instructor accounts.

Generated by OpenCVE AI on October 10, 2026 at 03:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Academy LMS plugin to the latest version that includes the authorization check fix.
  • If the plugin cannot be updated immediately, temporarily disable the delete_lesson_comment AJAX entry point or revoke the instructor capability that allows comment deletion in the plugin settings.
  • Re‑evaluate user roles to ensure that only administrators can delete comments from courses they do not manage, and audit the comment deletion logs for suspicious activity.

Generated by OpenCVE AI on October 10, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct. This is exploitable by any user registered as an Academy instructor for at least one course, as they can supply their own course_id to pass the instructor check while targeting comments belonging to entirely different courses.
Title Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T02:26:30.717Z

Reserved: 2026-10-02T16:09:59.143Z

Link: CVE-2026-104915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T03:17:04.107

Modified: 2026-10-10T03:17:04.107

Link: CVE-2026-104915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T03:30:16Z

Weaknesses