VYPR
Unrated severityNVD Advisory· Published Jun 16, 2026

WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability

CVE-2026-39598

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server.

This issue affects Academy LMS Pro: from n/a before 3.5.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1