Komodo Cyber Security[verified]@KomodosecActive Exploitation
The post reports that CVE-2025-15521, a critical flaw in Academy LMS with CVSS 9.8, is being actively exploited for admin takeover, but no patch or PoC details are provided.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
CVE-2025-15521 is a critical vulnerability in The Academy LMS plugin that allows unauthenticated attackers to hijack admin accounts, enabling full site takeover; immediate patching or disabling of the plugin is strongly recommended.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
The advisory highlights CVE‑2025‑15521, a 9.8‑rated flaw in the Academy LMS WordPress plugin that permits unauthenticated account takeover via a password‑reset bug, and recommends updating to the latest version to mitigate the risk.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
The post announces a critical privilege escalation flaw in the Academy LMS plugin, provides details of the vulnerability and a patch release (v3.5.1), and advises remedial actions.