CVE-2025-15521
CRITICAL EXPLOITEDAcademy LMS - WordPress LMS Plugin <3.5.0 - Privilege Escalation
Title source: llmExploitation Summary
CVE-2025-15521 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Nxploited.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2025-15521, targeting an insecure password reset flow in Academy LMS 3.5.0. The script automates the extraction of reset keys, triggers vulnerable reset handlers, and verifies access via strict login checks.
Description
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password and relying solely on a publicly-exposed nonce for authorization. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and gain access to their account.
Exploits (1)
This repository contains a functional Python exploit for CVE-2025-15521, targeting an insecure password reset flow in Academy LMS 3.5.0. The script automates the extraction of reset keys, triggers vulnerable reset handlers, and verifies access via strict login checks.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H