What is CVE-2026-16563?
CVE-2026-16563 is a vulnerability in the Academy LMS WordPress plugin before version 3.8.3 that fails to verify course enrollment or lesson publication status via its REST API. This allows subscriber-level users to disclose the content of arbitrary lessons. Updating the plugin to version 3.8.3 or later is recommended.
Azərbaycanca: CVE-2026-16563 Academy LMS WordPress plaqinində (3.8.3-dən əvvəlki versiyalarda) REST API vasitəsilə hər hansı dərsin məzmununu ifşa etməyə imkan verən zəiflikdir. Bu, abunəçi səviyyəli istifadəçilərə qeydiyyatdan keçmədikləri və ya dərc olunmamış dərslərə baxmaq imkanı yaradır. Plaqini ən azı 3.8.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What REST API function does CVE-2026-16563 break in the Academy LMS plugin?
It fails to verify course enrollment or lesson publication status via its REST API, allowing subscriber-level users to view the content of unenrolled lessons.
To which version should Academy LMS be updated to mitigate CVE-2026-16563?
It is recommended to update to version 3.8.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.