CVE-2026-14184: Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR
Published Jul 21, 2026
·Updated
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, allowing authenticated users with subscriber-level access to read and modify other users' lesson notes and mark other users' lesson content as completed.
Affected Software
1 affected component
Academy LMS WordPress plugin<3.8.1
Event History
Jul 21, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14184?
The severity of CVE-2026-14184 is medium with a CVSS score of 5.4.
2
How do I fix CVE-2026-14184?
To fix CVE-2026-14184, update the Academy LMS WordPress plugin to version 3.8.1 or later.
3
What types of user access are affected by CVE-2026-14184?
CVE-2026-14184 affects authenticated users with subscriber-level access.
4
What kind of attacks can CVE-2026-14184 allow?
CVE-2026-14184 allows authenticated users to read and modify other users' lesson notes and progress.
5
Which versions of the Academy LMS plugin are vulnerable to CVE-2026-14184?
Versions of the Academy LMS plugin prior to 3.8.1 are vulnerable to CVE-2026-14184.