CVE-2026-104022
Description
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the add_child() function calling add_role('academy_student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP_Error. This makes it possible for authenticated attackers with the academy_guardian role or higher to elevate any existing WordPress account — including their own — to the academy_student role, gaining edit_posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload_files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email_exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add_role() call has already executed and is never reversed, the academy_student role grant on their own account persists permanently.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
6- plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/guardian/rest-api.phpnvd
- plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/guardian/rest-api.phpnvd
- plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/guardian/rest-api.phpnvd
- plugins.trac.wordpress.org/browser/academy/tags/4.0.2/includes/guardian/store.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/a54dd9e5-59e7-4655-9f64-e198deda1383nvd
News mentions
0No linked articles in our index yet.