CyberRota Analysis
AI-GeneratedThe Academy LMS WordPress plugin prior to version 3.8.1 is vulnerable due to inadequate verification of user identifiers in its lesson AJAX handlers, enabling authenticated users with subscriber-level access to access and alter other users' lesson notes and completion statuses. This could lead to unauthorized data manipulation and privacy concerns within the learning management system. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.