CVE-2025-15521Patch

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password and relying solely on a publicly-exposed nonce for authorization. This makes it possible for unauthenticated attackers to change arbitrary user's password, including administrators, and gain access to their account.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Peaked 3d ago at 1 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-28: 1Active Exploitation · 2026-02-28: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-28: 102-0602-0802-0902-28
Signal classification2 categories
Patch
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-061
Patch1
2026-02-081
Patch1
2026-02-091
Patch1
2026-02-281
Active Exploitation1
Full discourse4 posts
  • Komodo Cyber Security@Komodosec
    Active Exploitation

    #VulnerabilityReport #AcademyLMS CVE-2025-15521 (CVSS 9.8): Critical Academy LMS Flaw Exploited for Admin Takeover https://securityonline.info/cve-2025-15521-cvss-9-8-critical-academy-lms-flaw-exploited-for-admin-takeover/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The post reports that CVE-2025-15521, a critical flaw in Academy LMS with CVSS 9.8, is being actively exploited for admin takeover, but no patch or PoC details are provided.

    00020185
    1.5K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CRITICAL WORDPRESS ALERT: CVE-2025-15521 (CVSS 9.8) allows unauthenticated attackers to hijack ADMIN accounts in "The Academy LMS" plugin. 🔓 https://nvd.nist.gov/vuln/detail/CVE-2025-15521 ⚠️ Affected: Versions ≤ 3.5.0 ⚡ Impact: Full Site Takeover PATCH NOW or disable the plugin immediately! 🛑 Keep your website malware-free https://quttera.com/wordpress-malware-scanner #InfoSec #WordPressSecurity #CyberAlert #CVE202515521 #CVE

    Post summary

    CVE-2025-15521 is a critical vulnerability in The Academy LMS plugin that allows unauthenticated attackers to hijack admin accounts, enabling full site takeover; immediate patching or disabling of the plugin is strongly recommended.

    0100076
    37 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical Security Alert: CVE-2025-15521 A 9.8 CRITICAL vulnerability has been found in the Academy LMS WordPress plugin (up to v3.5.0). Unauthenticated attackers can take over ANY account, including administrators, by exploiting a password reset flaw. ✅ Action: Update to the latest version immediately! Protect your website: https://wordpress.org/extend/plugins/quttera-web-malware-scanner/ #CyberSecurity #WordPress #InfoSec #Vulnerability #AcademyLMS #CVE202515521 #Malware #CVE

    Post summary

    The advisory highlights CVE‑2025‑15521, a 9.8‑rated flaw in the Academy LMS WordPress plugin that permits unauthenticated account takeover via a password‑reset bug, and recommends updating to the latest version to mitigate the risk.

    0000055
    37 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical #WordPress Vulnerability — CVE-2025-15521 A serious privilege escalation flaw in the Academy LMS – WordPress LMS Plugin (≤ 3.5.0) lets unauthenticated attackers reset any user’s password, including administrators, by abusing improper identity validation — enabling full site takeover. https://nvd.nist.gov/vuln/detail/CVE-2025-15521 ⚠️ Severity: CRITICAL 9.8 — network exploitable with no login required. 🔧 Fix: • Update Academy LMS to v3.5.1 or later (when available) • Review and secure password reset flows • Audit admin accounts and disable unused LMS features Protect your WordPress eCommerce or LMS site with deep malware & attacker behavior detection: 👉 https://quttera.com/wordpress-malware-scanner Secure your website with full perimeter security. #WordPress #CVE #PrivilegeEscalation #PluginSecurity #LMS #WebSecurity #eCommerceSecurity #FullPerimeterSecurity #MalwareDetection

    Post summary

    The post announces a critical privilege escalation flaw in the Academy LMS plugin, provides details of the vulnerability and a patch release (v3.5.1), and advises remedial actions.

    0000052
    37 followersView on X

Explore more