CVE-2025-59562: WordPress Academy LMS Plugin <= 3.3.4 - Insecure Direct Object References (IDOR) Vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS Academy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Academy LMS: from n/a through 3.3.4.
Other sources
Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.3.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59562?
CVE-2025-59562 has been classified with a severity that indicates significant risk due to authorization bypass issues.
How do I fix CVE-2025-59562?
To mitigate CVE-2025-59562, ensure that your Academy LMS is updated to the latest version beyond 3.3.4 where the vulnerability is addressed.
Who is affected by CVE-2025-59562?
CVE-2025-59562 affects users of Academy LMS and the WordPress Academy LMS Plugin versions up to 3.3.4.
What type of vulnerability is CVE-2025-59562?
CVE-2025-59562 is an 'Authorization Bypass Through User-Controlled Key' vulnerability.
What consequences could arise from CVE-2025-59562?
Exploitation of CVE-2025-59562 could allow attackers to gain unauthorized access to restricted resources in Academy LMS.