PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104915 kodezen CVE debrief

The Academy LMS plugin for WordPress, versions up to and including 4.0.3, is vulnerable to authorization bypass. This vulnerability allows authenticated attackers with custom-level access to delete arbitrary Academy lesson comments and their replies across courses they do not instruct. The plugin fails to properly verify user authorization for comment deletion, enabling attackers to supply their own course_id to bypass instructor checks and target comments in different courses. This issue affects WordPress installations with the Academy LMS plugin, particularly those with custom-level users. Defenders managing these installations should assess exposure and prioritize remediation to

Vendor
kodezen
Product
Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-11
Advisory published
2026-10-10
Advisory updated
2026-10-11

Who should care

Defenders managing WordPress installations with the Academy LMS plugin, especially those with custom-level users, should assess exposure and prioritize remediation. This involves verifying the version of the plugin, restricting access to sensitive functions, and monitoring for suspicious activity. Additionally, defenders should implement compensating controls for exposed systems and review relevant logs to ensure the security of their environments. Priorit

Why it matters

The Academy LMS plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers with custom-level access to delete arbitrary Academy lesson comments and their replies across courses they do not instruct. Defenders should verify and remediate this vulnerability, especially those managing WordPress installations with custom-level users.

  • Authenticated attackers can delete arbitrary lesson comments and their replies across courses they do not instruct
  • Requires verification of user authorization for comment deletion
  • Custom-level users can exploit this vulnerability
  • Remediation priority for WordPress installations with Academy LMS plugin

Technical summary

The Academy LMS plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows authenticated attackers with custom-level access and above to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct by supplying their own course_id to pass the instructor check. The vulnerability exists in Academy LMS plugin versions up to and including 4.0.3. Authenticated attackers can exploit this by targeting comments belonging to entirely different courses, highlighting the need for defenders to verify and remediate this vulnerability, especially those managing WordPres

Defensive priority

Medium priority for defenders to verify and remediate this vulnerability, especially those managing WordPress installations with the Academy LMS plugin.

Recommended defensive actions

  • Verify the version of the Academy LMS plugin and update to a patched version if necessary.
  • Restrict access to the delete_lesson_comment AJAX function.
  • Monitor for suspicious activity related to comment deletion.
  • Implement additional authentication and authorization checks for custom-level users.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability exists in Academy LMS plugin versions up to and including 4.0.3. Authenticated attackers with custom-level access can delete arbitrary Academy lesson comments and their replies across courses they do not instruct by supplying their own course_id to pass the instructor check.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104915 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104915

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104915 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104915

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Commen

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104915.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/ajax/miscellaneous.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/classes/abstract-ajax-handler.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/traits/courses.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.