Impact
The vulnerability is a missing authorization flaw that allows an attacker to exploit incorrectly configured access control security levels within the Academy LMS plugin. Because the plugin does not enforce proper privilege checks, users who achieve low or no authorization can reach administrative interfaces, read or modify course content, user data, and potentially change configuration settings.
Affected Systems
Affected products are Kodezen LLC’s Academy LMS WordPress plugin versions from the earliest release through 3.5.3. Any WordPress installation that uses this plugin version range is potentially vulnerable; the specific affected version metadata is not provided beyond the upper bound 3.5.3.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity. The EPSS is below 1%, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is likely web‑based: an authenticated or even anonymous user can potentially access administrative pages if the plugin’s security levels are misconfigured or insufficient. Without remediation, an attacker can gain unauthorized access and potentially elevate privileges within the LMS.
OpenCVE Enrichment