CVE-2026-104022: Academy LMS <= 4.0.3 - Authenticated (Custom+) Privilege Escalation to add_child REST endpoint

Published Oct 10, 2026
·
Updated

The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the addchild() function calling addrole('academystudent') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WPError. This makes it possible for authenticated attackers with the academyguardian role or higher to elevate any existing WordPress account — including their own — to the academystudent role, gaining editposts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, uploadfiles (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, emailexists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the addrole() call has already executed and is never reversed, the academystudent role grant on their own account persists permanently.

Affected Software

1 affected component
Academy LMS Academy LMS<=4.0.3

Event History

Oct 10, 2026
CVE Published
via MITRE·02:26 AM
Data Sourced
via MITRE·02:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which accounts can exploit this issue?

An authenticated WordPress user must have the academy_guardian role or a higher role. The issue can be used to grant the academy_student role to any existing WordPress account, including the attacker's own account.

2

What additional access does the academy_student role provide?

The role provides edit_posts capability, equivalent to Contributor-level post editing. If the student file-upload setting is enabled, it also provides upload_files capability, equivalent to Author-level media upload access.

3

Does exploitation require creating a valid guardian-ward relationship?

No. Supplying the guardian's own email causes the relationship validation to reject the self-link, but the academy_student role has already been added and is not removed when validation fails.

4

How can I determine whether an account may have been affected?

Review existing WordPress accounts for the academy_student role, particularly accounts that also have the academy_guardian role. A guardian account with academy_student assigned may have obtained the role through the failed self-link path described in the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203