CVE-2025-68527: WordPress Academy LMS plugin <= 3.4.0 - Cross Site Scripting (XSS) vulnerability
Published Dec 24, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kodezen LLC Academy LMS academy allows Stored XSS.This issue affects Academy LMS: from n/a through <= 3.4.0.
Affected Software
2 affected components
Kodezen LLC Academy LMS<=3.4.0
wordpress/academy-lms<=3.4.0
Event History
Dec 24, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Nov 15, 58279
Event
via MITRE·06:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-68527?
The severity of CVE-2025-68527 is classified as high due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-68527?
To fix CVE-2025-68527, upgrade the Kodezen LLC Academy LMS to version 3.4.1 or later.
3
What versions of the Academy LMS are affected by CVE-2025-68527?
CVE-2025-68527 affects Kodezen LLC Academy LMS versions from n/a up to and including 3.4.0.
4
What type of vulnerability is CVE-2025-68527?
CVE-2025-68527 is a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-68527 lead to data theft?
Yes, if exploited, CVE-2025-68527 can allow attackers to steal sensitive user data through stored XSS.