Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104915— Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id

Quick assessment

Affected
kodezen Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning 插件在所有 4.0.3 及以下版本中存在授权绕过漏洞。该漏洞源于插件未正确验证用户是否有权执行某项操作。因此,具有自定义权限级别及以上身份的已认证攻击者可以永久删除任意 Academy 课程中由任何用户(包括管理员)发布的课程评论及其回复,即使用户并未负责这些课程。 该漏洞可被任何至少在一个课程中注册为“学院讲师”的用户利用。攻击者通过自行提供 参数,即可绕过

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104915

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Academy LMS <= 4.0.3 - Missing Authorization to Authenticated (Custom+) Arbitrary Academy Comment Deletion via delete_lesson_comment AJAX — Attacker-Controlled course_id vs. Target comment_id
Source: CVE Program / CVE List V5
Vulnerability Description
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to permanently delete arbitrary Academy lesson comments and their replies authored by any user, including administrators, across courses they do not instruct. This is exploitable by any user registered as an Academy instructor for at least one course, as they can supply their own course_id to pass the instructor check while targeting comments belonging to entirely different courses.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kodezen Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning 0 ~ 4.0.3 -

II. Public POCs for CVE-2026-104915

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104915

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104915 (2)

Vendor Advisories for CVE-2026-104915 (1)

Other References for CVE-2026-104915 (1)

Other References for CVE-2026-104915 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104915

No comments yet


Leave a comment