CVE-2024-35171: WordPress Academy LMS plugin <= 1.9.25 - Sensitive Data Exposure vulnerability
Published May 13, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.
Affected Software
3 affected components
Academy LMS<=1.9.25
WordPress Academy LMS plugin<=1.9.25
Kodezen Academy Lms Wordpress<1.9.26
Remediation
Information
Update to 1.9.26 or a higher version.
Event History
May 13, 2024
CVE Published
via MITRE·09:08 AM
Data Sourced
via MITRE·09:08 AM
RemedyDescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35171?
The severity of CVE-2024-35171 is considered high due to the exposure of sensitive information to unauthorized actors.
2
How do I fix CVE-2024-35171?
To fix CVE-2024-35171, upgrade to the latest version of Academy LMS or the Academy LMS plugin beyond version 1.9.25.
3
What versions of Academy LMS are affected by CVE-2024-35171?
CVE-2024-35171 affects Academy LMS versions up to and including 1.9.25.
4
What type of vulnerability is CVE-2024-35171?
CVE-2024-35171 is classified as an exposure of sensitive information vulnerability.
5
Who can be impacted by CVE-2024-35171?
All users of Academy LMS versions up to 1.9.25 could be impacted by CVE-2024-35171 if sensitive information is improperly exposed.