← Späť na vyhľadávanie CVE

CVE-2026-5348

Academy LMS

Popis

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.8.1. This is due to the -/topics- REST API endpoint being registered with a permission callback set to -__return_true-, allowing unauthenticated access to course curriculum data without verifying the course-s post status or user enrollment. This makes it possible for unauthenticated attackers to access detailed curriculum information for private, draft, scheduled, or password-protected courses by enumerating course IDs.

CVSS 5.3EPSS 0.262%Riziko 0.54
Zobraziť zdroj
Zverejnené
2026-07-02 06:16:14
Dotknuté verzie
<=3.8.1
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N