Plugin Vulnerability Hub
Plugin 11 known issues Latest disclosed Feb 17, 2026

Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Vulnerabilities

Review known vulnerability records for the WordPress plugin Academy LMS – WordPress LMS Plugin for Complete eLearning Solution (`academy`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-25372, CVE-2025-15521 and CVE-2025-68527, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
11
High or Critical
4
Patch Coverage
100%
Last Updated
Feb 24, 2026
Priority CVE Quick Links

Fast paths into Academy LMS – WordPress LMS Plugin for Complete eLearning Solution CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
11
CVE-2025-15521 Critical 3.5.1
CVE-2025-15521 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Authorization Bypass

Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover

CVE-2024-1505 High 1.9.20
CVE-2024-1505 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Privilege Escalation

Academy LMS – eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege Escalation

CVE-2024-37234 High 2.0.11
CVE-2024-37234 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Vulnerability

Academy LMS <= 2.0.10 - Open Redirect

CVE-2025-12099 High 3.3.9
CVE-2025-12099 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Vulnerability

Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses'

CVE-2025-68527 Medium 3.4.1
CVE-2025-68527 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Stored Cross-Site Scripting

Academy LMS <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-32714 Medium 1.9.17
CVE-2024-32714 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Vulnerability

Academy LMS <= 1.9.16 - Missing Authorization

CVE-2024-35171 Medium 1.9.26
CVE-2024-35171 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Sensitive Information Exposure

Academy LMS <= 1.9.25 - Unauthenticated Sensitive Information Exposure

CVE-2026-25372 Medium 3.5.4
CVE-2026-25372 Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Vulnerability

Academy LMS <= 3.5.3 - Missing Authorization

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Academy LMS – WordPress LMS Plugin for Complete eLearning Solution so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
11 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 3 high severity findings.
Recent CVEs
CVE-2026-25372, CVE-2025-15521 and CVE-2025-68527
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Academy LMS – WordPress LMS Plugin for Complete eLearning Solution

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-25372
CVE-2026-25372: Academy LMS <= 3.5.3 - Missing Authorization

The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.5.3. This makes it possible for authenticated attackers, with instructor-level access and above, to perform an unauthorize...

Published
Feb 17, 2026
Patched Release
3.5.4
Affected Versions
Versions up to 3.5.3
Next Step
Update to 3.5.4 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-15521
CVE-2025-15521: Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updatin...

Published
Jan 20, 2026
Patched Release
3.5.1
Affected Versions
Versions up to 3.5.0
Next Step
Update to 3.5.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-68527
CVE-2025-68527: Academy LMS <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Academy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to in...

Published
Dec 30, 2025
Patched Release
3.4.1
Affected Versions
Versions up to 3.4.0
Next Step
Update to 3.4.1 or newer if supported.
Plugin High Patched: Yes CVE-2025-12099
CVE-2025-12099: Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses'

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.3.8 via deserialization of untrusted input in the 'import_all_courses' function. This makes it possible for au...

Published
Nov 07, 2025
Patched Release
3.3.9
Affected Versions
Versions up to 3.3.8
Next Step
Update to 3.3.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-59562
CVE-2025-59562: Academy LMS <= 3.3.4 - Authenticated (Academy Instructor+) Insecure Direct Object Reference

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4 due to missing validation on a user controlled key. This makes it possible for authenticated a...

Published
Sep 22, 2025
Patched Release
3.3.5
Affected Versions
Versions up to 3.3.4
Next Step
Update to 3.3.5 or newer if supported.
Plugin Low Patched: Yes CVE-2024-38701
CVE-2024-38701: Academy LMS <= 2.0.4 - Missing Authorization

The Academy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the quiz_attempts_permissions_check() function in versions up to, and including, 2.0.4. This makes it possible for authenticated attackers, with academy instruct...

Published
Jul 11, 2024
Patched Release
2.0.5
Affected Versions
Versions up to 2.0.4
Next Step
Update to 2.0.5 or newer if supported.
Plugin High Patched: Yes CVE-2024-37234
CVE-2024-37234: Academy LMS <= 2.0.10 - Open Redirect

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.10. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated a...

Published
Jun 21, 2024
Patched Release
2.0.11
Affected Versions
Versions up to 2.0.10
Next Step
Update to 2.0.11 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-35171
CVE-2024-35171: Academy LMS <= 1.9.25 - Unauthenticated Sensitive Information Exposure

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.25. This makes it possible for unauthenticated attackers to extract sensitive user or configuration...

Published
May 10, 2024
Patched Release
1.9.26
Affected Versions
Versions up to 1.9.25
Next Step
Update to 1.9.26 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-33912
CVE-2024-33912: Academy LMS <= 1.9.16 - Missing Authorization

The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on afunction in versions up to, and including, 1.9.16. This makes it possible for authenticated attackers, with student-level access and above, to perform an unauthorized a...

Published
Apr 29, 2024
Patched Release
1.9.17
Affected Versions
Versions up to 1.9.16
Next Step
Update to 1.9.17 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-32714
CVE-2024-32714: Academy LMS <= 1.9.16 - Missing Authorization

The Academy LMS plugin for WordPress is vulnerable to unauthorized access due to insufficient validation on the enroll_course() function in versions up to, and including, 1.9.16. This makes it possible for authenticated attackers, with subscriber-level access and above, to enroll...

Published
Apr 22, 2024
Patched Release
1.9.17
Affected Versions
Versions up to 1.9.16
Next Step
Update to 1.9.17 or newer if supported.
Plugin High Patched: Yes CVE-2024-1505
CVE-2024-1505: Academy LMS – eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege Escalation

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This ma...

Published
Feb 21, 2024
Patched Release
1.9.20
Affected Versions
Versions up to 1.9.19
Next Step
Update to 1.9.20 or newer if supported.