WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Academy LMS

Academy LMS is the top-rated WordPress LMS plugin — create, sell & manage online courses with AI, quizzes, certificates & multi-instructor tools.

16Reported vulnerabilities
9.8Highest CVSS score
3.8.5Latest version
2,000+Active installs

What to do now

Update Academy LMS to 3.8.3 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 14, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-15521 Critical 9.8 0.4% 0 to 3.5.0 (inclusive) 3.5.1 January 21, 2026
CVE-2024-1505 High 8.8 0.8% Before 1.9.20 1.9.20 March 13, 2024
CVE-2024-37234 High 8.3 0.3% 2.0.10 and earlier 2.0.11 June 21, 2024
CVE-2025-12099 High 7.2 0.5% 0 to 3.3.8 (inclusive) 3.3.9 November 8, 2025
CVE-2025-68527 Medium 6.4 0.2% 3.4.0 and earlier 3.4.1 December 30, 2025
CVE-2024-35171 Medium 5.3 0.6% 1.9.25 and earlier 1.9.26 May 10, 2024
CVE-2024-32714 Medium 5.4 0.3% 1.9.16 and earlier 1.9.17 April 22, 2024
CVE-2026-5348 Medium 5.3 0.5% 0 to 3.8.1 (inclusive) 3.8.2 July 2, 2026
CVE-2026-12376 Medium 4.3 0.2% 3.8.2 and earlier August 4, 2026
CVE-2026-16563 Medium 4.3 0.2% 3.8.2 and earlier 3.8.3 July 24, 2026
CVE-2026-9341 Medium 4.3 0.4% 0 to 3.8.0 (inclusive) 3.8.1 July 14, 2026
CVE-2026-14184 Medium 4.3 0.2% 3.8.0 and earlier 3.8.1 June 30, 2026
CVE-2026-25372 Medium 4.3 0.2% 3.5.3 and earlier 3.5.4 February 17, 2026
CVE-2025-59562 Medium 4.3 0.4% 3.3.4 and earlier 3.3.5 September 22, 2025
CVE-2024-33912 Medium 4.3 0.4% 1.9.16 and earlier 1.9.17 April 29, 2024
CVE-2024-38701 Low 2.7 0.4% 2.0.4 and earlier 2.0.5 July 11, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.