目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-16563— Academy LMS <3.8.3 任意课程内容泄露漏洞

AI Predicted 6.5 Difficulty: Trivial EPSS 0.13% · P3

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
UnknownAcademy LMS< 3.8.3affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-16563の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
ソース: CVE Program / CVE List V5
脆弱性説明
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, allowing users with a self-service student (Subscriber-level) account to disclose the content of arbitrary lessons, including lessons of paid courses they are not enrolled in and unpublished (draft, pending, private) lessons.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
UnknownAcademy LMS 0 ~ 3.8.3 -

II. CVE-2026-16563の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-16563のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-16563 厂商安全公告 (1)

Same Patch Batch · Unknown · 2026-08-03 · 27 CVEs total

CVE-2026-15231TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
CVE-2026-16057Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from
CVE-2026-16274Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_blo
CVE-2026-15254Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admi
CVE-2025-15672Chama < 1.0.13 - Unauthenticated PHP Object Injection
CVE-2025-15673Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
CVE-2026-16532Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission For
CVE-2026-16534Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Admini
CVE-2026-16276Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_
CVE-2026-13340SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
CVE-2026-12872Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
CVE-2026-12965Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking
CVE-2026-14557SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
CVE-2026-16565Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute
CVE-2026-16060Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File
CVE-2026-16250Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
CVE-2026-15383Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
CVE-2026-15260Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion v
CVE-2026-15931Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber
CVE-2026-15930Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registratio

Showing 20 of 27 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-16563へのコメント

まだコメントはありません


コメントを残す