Medium 6.5
2026-02-19< 3.5.4
CVE-2026-25372
Minimum safe version
3.5.4
Update to 3.5.4 or later to address 11 fixable vulnerabilities
CVE-2026-25372
CVE-2025-15521
Academy LMS <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2025-12099
WordPress Academy LMS Plugin <= 3.3.4 is vulnerable to Insecure Direct Object References (IDOR)
CVE-2024-38701
CVE-2024-37234
CVE-2024-35171
CVE-2024-33912
CVE-2024-32714
CVE-2024-1505