Beveiligingsadvies

CVE-2026-14184

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-21 06:00:01
Laatst bijgewerkt 2026-07-21 15:43:25
Toegewezen door WPScan
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.