CVE 8.1 HIGH

Academy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login Addon_CVE-2025-11086

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.

Basic Information

ID CVE-2025-11086
Source Wordfence
Published Oct 22, 2025 at 11:25

Affected Product

Vendor academylms
Product Academy LMS Pro
Version *
Affected Versions academylms Academy LMS Pro *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.