Answer in brief
CVE-2026-104050 records a Unknown severity vulnerability in Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answers. The current sources do not mark it as known exploited. The current feed maps Unknown/Academy LMS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Academy LMS (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Academy LMSgeneric | >=0 <4.0.0 | 4.0.0 |
Published upstream
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 7, 2026
The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access before returning that question's answer options, allowing any authenticated user with access to a single course, such as an enrolled student, to read the quiz answer options of questions belonging to other courses they are not enrolled in.
Quoted source text, attributed separately from HOL analysis.