CVE-2026-104022
Received Received - Intake

Privilege Escalation in Academy LMS WordPress Plugin

Vulnerability report for CVE-2026-104022, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Wordfence

Description

The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the `add_child()` function calling `add_role('academy_student')` on any existing account resolved from the attacker-supplied `email` parameter before `Store::link()` validates the guardian-ward relationship, and failing to roll back that role write when `Store::link()` returns a `WP_Error`. This makes it possible for authenticated attackers with the `academy_guardian` role or higher to elevate any existing WordPress account β€” including their own β€” to the `academy_student` role, gaining `edit_posts` (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, `upload_files` (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, `email_exists()` resolves to their own user ID, causing `Store::link()` to reject the self-link, but because the `add_role()` call has already executed and is never reversed, the academy_student role grant on their own account persists permanently.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kodezen Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Academy LMS WordPress plugin allows authenticated attackers with the academy_guardian role or higher to escalate privileges of any existing WordPress account to the academy_student role. This happens because the add_child() function grants the academy_student role before validating the guardian-ward relationship, and fails to remove the role if validation fails. The attacker can gain edit_posts and upload_files capabilities.

Detection Guidance

Check WordPress user roles for unexpected 'academy_student' assignments. Review plugin logs for unauthorized role modifications. Use commands like 'wp user list' to list users and their roles in WordPress CLI.

Impact Analysis

If you use the Academy LMS plugin, an attacker could gain elevated privileges on your WordPress site. They could edit posts or upload files, potentially leading to unauthorized content changes, data theft, or further attacks. This requires the attacker to already have at least the academy_guardian role.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of sensitive data, violating GDPR's integrity and confidentiality principles or HIPAA's access controls. Unauthorized role escalation may result in data breaches, non-compliance with data protection requirements, and potential legal consequences.

Mitigation Strategies

Update the Academy LMS plugin to the latest version if available. Remove the 'academy_student' role from unintended users. Audit user roles and capabilities regularly. Disable file uploads for students if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104022. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart