CVE-2026-16563
Received Received - Intake

Academy LMS REST API Lesson Content Exposure Vulnerability

Vulnerability report for CVE-2026-16563, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
academy_lms wordpress_plugin to 3.8.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Academy LMS WordPress plugin before version 3.8.3 has a vulnerability in its REST API. It fails to check if a user is enrolled in a course or if a lesson is published before returning lesson content. This allows users with a basic Subscriber-level account to access private or unpublished lessons, including paid course content they shouldn't see.

Impact Analysis

If you use this plugin, attackers with minimal access could view restricted or paid course content without paying. Unpublished draft lessons may also be exposed, revealing upcoming content or internal materials before they are ready.

Mitigation Strategies

Update the Academy LMS WordPress plugin to version 3.8.3 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16563. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart