logo

CVE-2025-15521 (CVSS 9.8): Critical Academy LMS Flaw Exploited for Admin Takeover

ID: b4a55f31-dcb2-518a-ac9c-709e9cd9c61f

STIX ID: report--b4a55f31-dcb2-518a-ac9c-709e9cd9c61f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** A critical vulnerability (CVE-2025-15521, CVSS 9.8) in the Academy LMS WordPress plugin (versions ≤ 3.5.0) permits unauthenticated attackers to reset passwords and seize administrator accounts by exploiting a publicly exposed nonce; Wordfence has observed active exploitation attempts and blocked 76 attacks in a 24‑hour period, and administrators are strongly advised to update to the patched plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.