SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-14184

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Academy LMS WordPress plugin prior to version 3.8.1 is vulnerable due to inadequate verification of user identifiers in its lesson AJAX handlers, enabling authenticated users with subscriber-level access to access and alter other users' lesson notes and completion statuses. This could lead to unauthorized data manipulation and privacy concerns within the learning management system. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14184
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
WordPress

Original NVD Description

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.