The aBlocks plugin, developed by Kodezen LLC, is vulnerable to Incorrect Privilege Assignment, which could lead to Privilege Escalation. This issue affects aBlocks versions from n/a through 2.9.1. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Users of aBlocks plugin versions prior to 2.9.1 should assess and mitigate this vulnerability to prevent potential privilege escalati [truncated]
CVE-2026-39598 is a high-severity vulnerability (CVSS Score: 8) in Academy LMS Pro, a learning management system plugin. The vulnerability allows unrestricted file uploads with dangerous types, potentially enabling attackers to upload web shells to the web server. This issue affects Academy LMS Pro versions from n/a to 3.5.2. The vulnerability was published on June 17, 2026, and last modified on the same day.