CVE-2026-16563: CWE-284 Improper Access Control in Academy LMS
Academy LMS WordPress plugin versions before 3.8.3 have an improper access control vulnerability in their REST API. This flaw allows users with Subscriber-level accounts to access lesson content without verifying enrollment or lesson publication status. As a result, unauthorized users can view lessons from paid courses they are not enrolled in, including unpublished lessons in draft, pending, or private states.
AI Analysis
Technical Summary
The Academy LMS WordPress plugin prior to version 3.8.3 does not properly enforce access controls when returning individual lesson data via its REST API. Specifically, it fails to verify whether a requesting user is enrolled in the course or whether the lesson is published. This allows users with Subscriber-level privileges to retrieve content from arbitrary lessons, including those from paid courses they have not purchased and lessons that are unpublished (draft, pending, or private). The vulnerability is classified under CWE-284 (Improper Access Control) and has a CVSS v3.1 base score of 6.5, indicating a medium severity level. No official patch or remediation guidance is currently provided in the available data.
Potential Impact
Unauthorized disclosure of lesson content can occur, exposing paid course materials and unpublished lessons to users without proper enrollment or permissions. This compromises the confidentiality of course content and may impact the business model of content providers using Academy LMS. There is no indication of impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Subscriber-level user access where possible and monitor for unauthorized access attempts. Avoid exposing the REST API endpoints publicly if feasible.
CVE-2026-16563: CWE-284 Improper Access Control in Academy LMS
Description
Academy LMS WordPress plugin versions before 3.8.3 have an improper access control vulnerability in their REST API. This flaw allows users with Subscriber-level accounts to access lesson content without verifying enrollment or lesson publication status. As a result, unauthorized users can view lessons from paid courses they are not enrolled in, including unpublished lessons in draft, pending, or private states.
CVSS v3.1
Score 6.5medium
Affected software
Academy LMS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Academy LMS WordPress plugin prior to version 3.8.3 does not properly enforce access controls when returning individual lesson data via its REST API. Specifically, it fails to verify whether a requesting user is enrolled in the course or whether the lesson is published. This allows users with Subscriber-level privileges to retrieve content from arbitrary lessons, including those from paid courses they have not purchased and lessons that are unpublished (draft, pending, or private). The vulnerability is classified under CWE-284 (Improper Access Control) and has a CVSS v3.1 base score of 6.5, indicating a medium severity level. No official patch or remediation guidance is currently provided in the available data.
Potential Impact
Unauthorized disclosure of lesson content can occur, exposing paid course materials and unpublished lessons to users without proper enrollment or permissions. This compromises the confidentiality of course content and may impact the business model of content providers using Academy LMS. There is no indication of impact on integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Subscriber-level user access where possible and monitor for unauthorized access attempts. Avoid exposing the REST API endpoints publicly if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-22T12:28:05.699Z
- State
- PUBLISHED
Threat ID: 6a703650bf32cb7a341831ac
Added to database: 08/03/2026, 06:33:52 UTC
Last enriched: 08/10/2026, 15:12:33 UTC
Last updated: 09/17/2026, 22:01:33 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.