- Description
- The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password and relying solely on a publicly-exposed nonce for authorization. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and gain access to their account.
- Source
- security@wordfence.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-639
- Hype score
- Not currently trending
#VulnerabilityReport #AcademyLMS CVE-2025-15521 (CVSS 9.8): Critical Academy LMS Flaw Exploited for Admin Takeover https://t.co/n5cqAF7b8F
@Komodosec
28 Feb 2026
132 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Security Alert: CVE-2025-15521 A 9.8 CRITICAL vulnerability has been found in the Academy LMS WordPress plugin (up to v3.5.0). Unauthenticated attackers can take over ANY account, including administrators, by exploiting a password reset flaw. ✅ Action: Update to the
@MNovofastovsky
9 Feb 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CRITICAL WORDPRESS ALERT: CVE-2025-15521 (CVSS 9.8) allows unauthenticated attackers to hijack ADMIN accounts in "The Academy LMS" plugin. 🔓 https://t.co/wfQQNmXdJ5 ⚠️ Affected: Versions ≤ 3.5.0 ⚡ Impact: Full Site Takeover PATCH NOW or disable the plugin immediate
@MNovofastovsky
8 Feb 2026
60 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical #WordPress Vulnerability — CVE-2025-15521 A serious privilege escalation flaw in the Academy LMS – WordPress LMS Plugin (≤ 3.5.0) lets unauthenticated attackers reset any user’s password, including administrators, by abusing improper identity validation — enab
@MNovofastovsky
6 Feb 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15521 (CVSS:9.8, CRITICAL) is Received. The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e..https://t.co/8WWV7mtt9Q #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
26 Jan 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15521: Critical Admin Takeover Vulnerability in Academy LMS Plugin Exposes Thousands of eLearning Sites Read the full report on - https://t.co/ankCf7hfdc https://t.co/on5stsg9vn
@cyberbivash
22 Jan 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15521 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions… https://t.co/mgcy8InWX6
@CVEnew
21 Jan 2026
352 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[CVE-2025-15521: CRITICAL] WordPress LMS Plugin for eLearning is at risk! The Academy LMS Plugin up to version 3.5.0 allows unauthorized attackers to change any user's password, including admins. Cybersecuri...#cve,CVE-2025-15521,#cybersecurity https://t.co/0yHIowUtgp https://t.c
@CveFindCom
21 Jan 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-15521: Academy LMS – WordPress LMS Plug... Academy LMS exposes admin access through a trivial nonce-only auth bypass - the password reset function lacks proper id... https://t.co/aDC46mQqJz #netsec #vulnerability #CVE #sysadmin #zeroday
@0dayPublishing
21 Jan 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes