What is CVE-2026-12376?
The Academy LMS WordPress plugin through version 3.8.2 fails to restrict access to quiz attempt records, allowing any authenticated user (subscriber+ role, enrolled in any course) to read all users' quiz attempts and personal data. Plugin owners should immediately apply the security update or constrain this temporary exposure.
Azərbaycanca: Academy LMS WordPress plaginində (3.8.2 versiyasına qədər) boşluq aşkarlanıb: hər hansı autentifikasiya olunmuş istifadəçi (subscriber və yuxarı rol, ən azı bir kursa yazılmış) bütün istifadəçilərin quiz cəhdlərini və şəxsi məlumatlarını oxuya bilir. Plagin sahibləri dərhal təhlükəsizlik yeniləməsini tətbiq etməli və ya bu müvəqqəti riski məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What level of access is required to exploit CVE-2026-12376?
To exploit this vulnerability, a user must have at least a subscriber role in the Academy LMS WordPress plugin and be enrolled in any course.
What data can be accessed through CVE-2026-12376?
This vulnerability allows an authenticated user to read all users' quiz attempts and personal data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.