CVE-2025-15521

Published Jan 21, 2026

Last updated 9 days ago

Overview

Description
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password and relying solely on a publicly-exposed nonce for authorization. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and gain access to their account.
Source
security@wordfence.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@wordfence.com
CWE-639

Social media

Hype score
Not currently trending
  1. #VulnerabilityReport #AcademyLMS CVE-2025-15521 (CVSS 9.8): Critical Academy LMS Flaw Exploited for Admin Takeover https://t.co/n5cqAF7b8F

    @Komodosec

    28 Feb 2026

    132 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Critical Security Alert: CVE-2025-15521 A 9.8 CRITICAL vulnerability has been found in the Academy LMS WordPress plugin (up to v3.5.0). Unauthenticated attackers can take over ANY account, including administrators, by exploiting a password reset flaw. ✅ Action: Update to the

    @MNovofastovsky

    9 Feb 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CRITICAL WORDPRESS ALERT: CVE-2025-15521 (CVSS 9.8) allows unauthenticated attackers to hijack ADMIN accounts in "The Academy LMS" plugin. 🔓 https://t.co/wfQQNmXdJ5 ⚠️ Affected: Versions ≤ 3.5.0 ⚡ Impact: Full Site Takeover PATCH NOW or disable the plugin immediate

    @MNovofastovsky

    8 Feb 2026

    60 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Critical #WordPress Vulnerability — CVE-2025-15521 A serious privilege escalation flaw in the Academy LMS – WordPress LMS Plugin (≤ 3.5.0) lets unauthenticated attackers reset any user’s password, including administrators, by abusing improper identity validation — enab

    @MNovofastovsky

    6 Feb 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-15521 (CVSS:9.8, CRITICAL) is Received. The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e..https://t.co/8WWV7mtt9Q #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    26 Jan 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-15521: Critical Admin Takeover Vulnerability in Academy LMS Plugin Exposes Thousands of eLearning Sites Read the full report on - https://t.co/ankCf7hfdc https://t.co/on5stsg9vn

    @cyberbivash

    22 Jan 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-15521 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions… https://t.co/mgcy8InWX6

    @CVEnew

    21 Jan 2026

    352 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. [CVE-2025-15521: CRITICAL] WordPress LMS Plugin for eLearning is at risk! The Academy LMS Plugin up to version 3.5.0 allows unauthorized attackers to change any user's password, including admins. Cybersecuri...#cve,CVE-2025-15521,#cybersecurity https://t.co/0yHIowUtgp https://t.c

    @CveFindCom

    21 Jan 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CVE-2025-15521: Academy LMS – WordPress LMS Plug... Academy LMS exposes admin access through a trivial nonce-only auth bypass - the password reset function lacks proper id... https://t.co/aDC46mQqJz #netsec #vulnerability #CVE #sysadmin #zeroday

    @0dayPublishing

    21 Jan 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes