Missing Authorization in Academy LMS by Kodezen LLC
CVE-2026-25372

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 February 2026

What is CVE-2026-25372?

The Academy LMS by Kodezen LLC contains a missing authorization issue, which allows attackers to exploit incorrectly configured access control security levels. This vulnerability allows unauthorized access to sensitive functionalities, affecting versions up to and including 3.5.3. Users are advised to review their configurations and implement necessary security measures to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Academy LMS <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.