PT-2025-43064 · WordPress · Social Login+1

Thái An

·

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-11086

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Academy LMS – WordPress LMS Plugin for Complete eLearning Solution versions prior to 3.3.8
Description The Academy LMS plugin for WordPress does not properly validate a user's role before allowing user registration through the Social Login addon. This allows unauthenticated attackers to escalate their privileges to Administrator during the registration process.
Recommendations Update to version 3.3.8 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11086

Affected Products

Academy Lms
Social Login