CVE-2026-104050: Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers
The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user who has access to at least one Academy LMS course can exploit it. This includes an enrolled student or another user with comparable course access.
What information can an attacker obtain?
The attacker can retrieve answer options for quiz questions in other courses that they are not authorized or enrolled to access.
What condition makes an installation vulnerable?
Academy LMS versions before 4.0.0 are affected. Exploitation requires an authenticated account with access to at least one course.