User Identifier Verification Flaw in Academy LMS WordPress Plugin
CVE-2026-14184
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 21 July 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14184?
The Academy LMS plugin for WordPress prior to version 3.8.1 contains a significant security flaw in its lesson AJAX handlers. The vulnerability arises from the failure to verify the ownership of user-supplied identifiers, allowing authenticated users with minimal permissions, such as subscribers, to access and modify lesson notes of other users. This breach can enable unauthorized manipulation of lesson content and potentially compromise the integrity of user-specific educational data.
Affected Version(s)
Academy LMS 0 < 3.8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.