Junglewise Threat Intelligence

CVE-2026-39598: Kodezen LLC Academy LMS Pro unrestricted file upload

CVE-2026-39598 · Severity: high · CVSS 8 · Published 2026-06-17

Executive brief

Academy LMS Pro is a WordPress plugin used to create and manage online learning platforms. A security flaw allows an attacker with high-level permissions to upload malicious files, such as web shells, to the server. If exploited, this could allow an attacker to take full control of the website, access sensitive student or course data, and disrupt online operations.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Academy LMS Pro plugin for WordPress. The flaw allows an authenticated attacker with high privileges (such as a custom administrative or developer role) to bypass file type restrictions and upload dangerous files, including PHP web shells, to the web server. While the attack requires high privileges and specific conditions (reflected in the AC:H/PR:H vector), successful exploitation results in a complete compromise of the confidentiality, integrity, and availability of the host system. The issue is resolved in version 3.5.2.

Affected products

  • Kodezen LLC Academy LMS Pro before 3.5.2

Timeline

  • 2026-01-06: other: Vulnerability reported by researcher luc
  • 2026-04-16: advisory: Patchstack published initial advisory
  • 2026-06-17: disclosed: CVE published to NVD

References