CVE-2026-104022: Academy LMS <= 4.0.3 - Authenticated (Custom+) Privilege Escalation to add_child REST endpoint
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the addchild() function calling addrole('academystudent') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WPError. This makes it possible for authenticated attackers with the academyguardian role or higher to elevate any existing WordPress account — including their own — to the academystudent role, gaining editposts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, uploadfiles (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, emailexists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the addrole() call has already executed and is never reversed, the academystudent role grant on their own account persists permanently.
Affected Software
Event History
Frequently Asked Questions
Which accounts can exploit this issue?
An authenticated WordPress user must have the academy_guardian role or a higher role. The issue can be used to grant the academy_student role to any existing WordPress account, including the attacker's own account.
What additional access does the academy_student role provide?
The role provides edit_posts capability, equivalent to Contributor-level post editing. If the student file-upload setting is enabled, it also provides upload_files capability, equivalent to Author-level media upload access.
Does exploitation require creating a valid guardian-ward relationship?
No. Supplying the guardian's own email causes the relationship validation to reject the self-link, but the academy_student role has already been added and is not removed when validation fails.
How can I determine whether an account may have been affected?
Review existing WordPress accounts for the academy_student role, particularly accounts that also have the academy_guardian role. A guardian account with academy_student assigned may have obtained the role through the failed self-link path described in the issue.