CVE-2025-11086
HIGHAcademy LMS - WordPress LMS Plugin <3.3.7 - Privilege Escalation
Title source: llmDescription
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This makes it possible for unauthenticated attackers to update their role to Administrator when registering on the site.
Scores
CVSS v3
8.1
EPSS
0.0010
EPSS Percentile
26.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (1)
academylms/Academy LMS Pro
< 3.3.7
Published
Oct 22, 2025
Tracked Since
Feb 18, 2026