Browse all 4 CVE security advisories affecting Academy LMS. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Academy LMS serves as a learning management platform for educational institutions and corporate training programs. Historically, the system has been susceptible to multiple vulnerability classes including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. With four CVEs currently documented, these issues have allowed attackers to potentially execute arbitrary code, manipulate user sessions, and gain unauthorized administrative access. While no major public security incidents have been widely reported, the consistent appearance of critical vulnerabilities in the platform's history suggests a need for rigorous security updates and input validation protocols to maintain system integrity and protect sensitive educational data.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-38701 | WordPress Academy LMS plugin <= 2.0.4 - Broken Access Control vulnerability — Academy LMSCWE-639 | 4.3 | Medium | 2024-07-22 |
| CVE-2024-32714 | WordPress Academy LMS plugin <= 1.9.16 - Broken Access Control vulnerability — Academy LMSCWE-862 | 4.3 | Medium | 2024-06-09 |
| CVE-2024-35171 | WordPress Academy LMS plugin <= 1.9.25 - Sensitive Data Exposure vulnerability — Academy LMSCWE-200 | 5.3 | Medium | 2024-05-13 |
| CVE-2024-33912 | WordPress Academy LMS plugin <= 1.9.16 - Broken Access Control on Paid Courses vulnerability — Academy LMSCWE-862 | 7.1 | High | 2024-05-06 |
This page lists every published CVE security advisory associated with Academy LMS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.