CVE-2024-33912: WordPress Academy LMS plugin <= 1.9.16 - Broken Access Control on Paid Courses vulnerability
Published May 6, 2024
·Updated
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.
Affected Software
3 affected components
Academy LMS<=1.9.16
WordPress Academy LMS plugin<=1.9.16
Kodezen Academy Lms Wordpress<1.9.17
Remediation
Information
Update to 1.9.17 or a higher version.
Event History
May 6, 2024
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 9, 57065
Event
via NVD·03:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-33912?
CVE-2024-33912 is classified as a missing authorization vulnerability with potential impact on user privacy and content access.
2
How do I fix CVE-2024-33912?
To fix CVE-2024-33912, update Academy LMS or the WordPress Academy LMS plugin to version 1.9.17 or later.
3
Which versions are affected by CVE-2024-33912?
CVE-2024-33912 affects Academy LMS versions up to and including 1.9.16.
4
What kind of issue does CVE-2024-33912 represent?
CVE-2024-33912 represents a broken access control vulnerability that allows unauthorized access to paid courses.
5
Who is impacted by CVE-2024-33912?
Users of Academy LMS and the WordPress Academy LMS plugin up to version 1.9.16 are potentially impacted by CVE-2024-33912.