PatchSiren cyber security CVE debrief
CVE-2026-104915 kodezen CVE debrief
The Academy LMS plugin for WordPress, versions up to and including 4.0.3, is vulnerable to authorization bypass. This vulnerability allows authenticated attackers with custom-level access to delete arbitrary Academy lesson comments and their replies across courses they do not instruct. The plugin fails to properly verify user authorization for comment deletion, enabling attackers to supply their own course_id to bypass instructor checks and target comments in different courses. This issue affects WordPress installations with the Academy LMS plugin, particularly those with custom-level users. Defenders managing these installations should assess exposure and prioritize remediation to
- Vendor
- kodezen
- Product
- Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-11
Who should care
Defenders managing WordPress installations with the Academy LMS plugin, especially those with custom-level users, should assess exposure and prioritize remediation. This involves verifying the version of the plugin, restricting access to sensitive functions, and monitoring for suspicious activity. Additionally, defenders should implement compensating controls for exposed systems and review relevant logs to ensure the security of their environments. Priorit
Why it matters
The Academy LMS plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with custom-level access to delete arbitrary Academy lesson comments and their replies across courses they do not instruct. Defenders should verify and remediate this vulnerability, especially those managing WordPress installations with custom-level users.
- Authenticated attackers can delete arbitrary lesson comments and their replies across courses they do not instruct
- Requires verification of user authorization for comment deletion
- Custom-level users can exploit this vulnerability
- Remediation priority for WordPress installations with Academy LMS plugin
Technical summary
The Academy LMS plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows authenticated attackers with custom-level access and above to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct by supplying their own course_id to pass the instructor check. The vulnerability exists in Academy LMS plugin versions up to and including 4.0.3. Authenticated attackers can exploit this by targeting comments belonging to entirely different courses, highlighting the need for defenders to verify and remediate this vulnerability, especially those managing WordPres
Defensive priority
Medium priority for defenders to verify and remediate this vulnerability, especially those managing WordPress installations with the Academy LMS plugin.
Recommended defensive actions
- Verify the version of the Academy LMS plugin and update to a patched version if necessary.
- Restrict access to the delete_lesson_comment AJAX function.
- Monitor for suspicious activity related to comment deletion.
- Implement additional authentication and authorization checks for custom-level users.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability exists in Academy LMS plugin versions up to and including 4.0.3. Authenticated attackers with custom-level access can delete arbitrary Academy lesson comments and their replies across courses they do not instruct by supplying their own course_id to pass the instructor check.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104915 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104915
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104915 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104915
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Commen
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104915.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/classes/abstract-ajax-handler.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/traits/courses.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.