CVE-2025-15521: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15521 is a critical privilege escalation vulnerability via account takeover in the Academy LMS – WordPress LMS Plugin for Complete eLearning Solution, developed by Kodezen. It affects all versions up to and including 3.5.0, allowing unauthenticated attackers to reset any user's password — including administrators — by exploiting a publicly-exposed nonce used as the sole authorization mechanism. The vulnerability was disclosed on January 20–21, 2026, with Wordfence as the CNA. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the plugin's password update function in includes/functions.php (around line 1581) relies solely on a nonce value for authorization without verifying the requesting user's identity (NVD, Wordfence). Because WordPress nonces are publicly accessible and can be obtained without authentication in certain contexts, an attacker can supply a valid nonce alongside an arbitrary target user ID to trigger a password change for any account. No authentication or additional privileges are required, and the attack is conducted entirely over the network with low complexity.

Impact

Successful exploitation grants an unauthenticated attacker full control over any WordPress user account, including site administrators, enabling complete WordPress installation takeover. An attacker with administrator access can install malicious plugins, modify site content, create backdoor accounts, exfiltrate sensitive user data (including PII of enrolled students in an LMS context), and pivot to underlying server infrastructure. The confidentiality, integrity, and availability of the entire WordPress site are all critically compromised (Wordfence).

Exploitability

A public proof-of-concept exploit has been published on GitHub (GitHub PoC), and the vulnerability has been referenced in threat intelligence reports covering high-impact plugin takeovers (Loginsoft). The EPSS score is approximately 0.074% (low probability of near-term mass exploitation), and there is no confirmed evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time. The vulnerability requires no authentication and no user interaction, making it trivially exploitable once an attacker identifies a vulnerable target.

Exploitation steps

  1. Reconnaissance: Use tools like WPScan, Shodan, or Google dorks to identify WordPress sites running the Academy LMS plugin version ≤ 3.5.0.
  2. Obtain a valid nonce: Access any publicly available page on the target WordPress site that exposes the plugin's nonce (e.g., a course enrollment or profile page), and extract the nonce value from the page source or API response.
  3. Identify target user: Enumerate WordPress user IDs or usernames (e.g., via the WordPress REST API at /wp-json/wp/v2/users) to identify administrator accounts.
  4. Craft malicious password-reset request: Send an HTTP POST request to the plugin's password update endpoint, supplying the harvested nonce and the target administrator's user ID along with a new attacker-controlled password — without providing any authentication credentials.
  5. Authenticate as the victim: Log in to the WordPress admin panel (/wp-admin) using the target account's username and the newly set password, achieving full administrative control (Wordfence, GitHub PoC).

Indicators of compromise

  • Network: Unexpected POST requests to Academy LMS plugin endpoints (e.g., paths containing academy or lms in the URL) with user ID parameters and nonce values from unauthenticated sources; unusual login attempts to /wp-admin from unfamiliar IP addresses shortly after such requests.
  • Logs: WordPress authentication logs showing successful admin logins from new or unknown IP addresses; access logs recording POST requests to plugin AJAX handlers (wp-admin/admin-ajax.php) with action parameters related to password updates from unauthenticated sessions.
  • File System: Newly installed plugins or themes not authorized by site administrators; new PHP files or web shells in the WordPress uploads or plugin directories.
  • User Accounts: Unexpected changes to administrator account passwords or email addresses; new administrator-level user accounts created without authorization; modifications to existing user roles.

Mitigation and workarounds

Organizations should update the Academy LMS plugin to a version beyond 3.5.0 immediately once a patched release is available from the developer (Kodezen). As an interim measure, consider disabling the plugin if it is not critical to operations, or restrict access to the WordPress installation via IP allowlisting or a Web Application Firewall (WAF) with rules targeting suspicious password-reset requests. Audit all administrator accounts for unauthorized access or password changes, and enable WordPress activity logging to detect anomalous authentication events (Wordfence).

Community reactions

Wordfence, the CNA for this CVE, published a detailed vulnerability entry and included it in their weekly WordPress vulnerability report for January 19–25, 2026 (Wordfence Blog). Loginsoft highlighted the vulnerability in a threat intelligence roundup titled "From Zero-Day Exploitation to Plugin Takeovers," characterizing it as a high-impact threat (Loginsoft). Security news outlet SecurityOnline.info covered the flaw with the headline "CVSS 9.8 Critical: Academy LMS Flaw Exploited for Admin Takeover," and the vulnerability received social media attention on Mastodon and Bluesky from security community accounts.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management