The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Academylms
Academylms academy Lms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Academylms
Academylms academy Lms Wordpress Wordpress wordpress |
Fri, 31 Jul 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results. | |
| Title | Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-31T06:00:11.328Z
Reserved: 2026-06-16T08:32:05.603Z
Link: CVE-2026-12376
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T08:00:04Z