CVE-2026-104049

CVE-2026-104049 published: The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST API routes, allowing users with a self-registerable student account to read the full content of ar...

View full NVD advisory → ← Back to CVE watch