
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15521 is a critical privilege escalation vulnerability via account takeover in the Academy LMS – WordPress LMS Plugin for Complete eLearning Solution, developed by Kodezen. It affects all versions up to and including 3.5.0, allowing unauthenticated attackers to reset any user's password — including administrators — by exploiting a publicly-exposed nonce used as the sole authorization mechanism. The vulnerability was disclosed on January 20–21, 2026, with Wordfence as the CNA. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, NVD).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the plugin's password update function in includes/functions.php (around line 1581) relies solely on a nonce value for authorization without verifying the requesting user's identity (NVD, Wordfence). Because WordPress nonces are publicly accessible and can be obtained without authentication in certain contexts, an attacker can supply a valid nonce alongside an arbitrary target user ID to trigger a password change for any account. No authentication or additional privileges are required, and the attack is conducted entirely over the network with low complexity.
Successful exploitation grants an unauthenticated attacker full control over any WordPress user account, including site administrators, enabling complete WordPress installation takeover. An attacker with administrator access can install malicious plugins, modify site content, create backdoor accounts, exfiltrate sensitive user data (including PII of enrolled students in an LMS context), and pivot to underlying server infrastructure. The confidentiality, integrity, and availability of the entire WordPress site are all critically compromised (Wordfence).
A public proof-of-concept exploit has been published on GitHub (GitHub PoC), and the vulnerability has been referenced in threat intelligence reports covering high-impact plugin takeovers (Loginsoft). The EPSS score is approximately 0.074% (low probability of near-term mass exploitation), and there is no confirmed evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time. The vulnerability requires no authentication and no user interaction, making it trivially exploitable once an attacker identifies a vulnerable target.
/wp-json/wp/v2/users) to identify administrator accounts./wp-admin) using the target account's username and the newly set password, achieving full administrative control (Wordfence, GitHub PoC).academy or lms in the URL) with user ID parameters and nonce values from unauthenticated sources; unusual login attempts to /wp-admin from unfamiliar IP addresses shortly after such requests.wp-admin/admin-ajax.php) with action parameters related to password updates from unauthenticated sessions.Organizations should update the Academy LMS plugin to a version beyond 3.5.0 immediately once a patched release is available from the developer (Kodezen). As an interim measure, consider disabling the plugin if it is not critical to operations, or restrict access to the WordPress installation via IP allowlisting or a Web Application Firewall (WAF) with rules targeting suspicious password-reset requests. Audit all administrator accounts for unauthorized access or password changes, and enable WordPress activity logging to detect anomalous authentication events (Wordfence).
Wordfence, the CNA for this CVE, published a detailed vulnerability entry and included it in their weekly WordPress vulnerability report for January 19–25, 2026 (Wordfence Blog). Loginsoft highlighted the vulnerability in a threat intelligence roundup titled "From Zero-Day Exploitation to Plugin Takeovers," characterizing it as a high-impact threat (Loginsoft). Security news outlet SecurityOnline.info covered the flaw with the headline "CVSS 9.8 Critical: Academy LMS Flaw Exploited for Admin Takeover," and the vulnerability received social media attention on Mastodon and Bluesky from security community accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."