CVE-2026-104022Medium· 5.4▾ SunlitThe Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the `add_child()` function calling `add_role('a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Academy LMS – AI Course Builder, Quizzes, Certificates & eLearning plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.0.3. This is due to the add_child() function calling add_role('academy_student') on any existing account resolved from the attacker-supplied email parameter before Store::link() validates the guardian-ward relationship, and failing to roll back that role write when Store::link() returns a WP_Error. This makes it possible for authenticated attackers with the academy_guardian role or higher to elevate any existing WordPress account — including their own — to the academy_student role, gaining edit_posts (Contributor-equivalent) capabilities and, when the student file-upload setting is enabled, upload_files (Author-equivalent) capabilities not granted to the guardian role. When a guardian supplies their own email address, email_exists() resolves to their own user ID, causing Store::link() to reject the self-link, but because the add_role() call has already executed and is never reversed, the academy_student role grant on their own account persists permanently.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2026-107645Critical· 9.1The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonc…
CVE-2026-108501Medium· 5.7ZTE Z80 Ultra has a system interface permission verification defect
CVE-2025-34251NoneTesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability
CVE-2025-10657NoneIn a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command restrictions featur…