CVE-2025-11086: Academy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login Addon
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11086?
CVE-2025-11086 is rated as a high severity vulnerability due to its privilege escalation risk.
How do I fix CVE-2025-11086?
To fix CVE-2025-11086, upgrade the Academy LMS Plugin for WordPress to version 3.3.8 or later.
What is the impact of CVE-2025-11086?
CVE-2025-11086 allows unauthorized users to register as higher-privileged users, leading to potential exploitation of the LMS system.
Is CVE-2025-11086 present in all versions of the Academy LMS Plugin?
Yes, CVE-2025-11086 affects all versions of the Academy LMS plugin up to and including 3.3.7.
Who is affected by CVE-2025-11086?
Administrators and users of the Academy LMS Plugin for WordPress are affected by CVE-2025-11086 due to the privilege escalation issue.