CVE-2026-104049: Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpoint
Published Oct 7, 2026
·Updated
The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of arbitrary lessons, including lessons of paid or private courses they are not enrolled in.
Affected Software
1 affected component
Academy LMS Academy LMS WordPress plugin<4.0.0
Event History
Oct 7, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any user who can create or obtain a student account can exploit it. The affected REST route does not verify that the user is enrolled in the requested course or owns the lesson content.
2
Are paid and private course lessons exposed?
Yes. A student account can read the full content of arbitrary lessons, including lessons belonging to paid or private courses where that account is not enrolled.
3
What versions are affected?
Academy LMS versions before 4.0.0 are affected.