Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint
CVE-2026-12376
Description
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access and above (enrolled in any single course) to read every user's quiz attempts across the whole site, including personal data such as IP addresses, names, registration dates and quiz results.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/8cdd6ab6-d523-4406-a0ef-d9b3b27e10c8/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.