Alerts
Critical WordPress LMS Plugin Flaw Under Active Exploitation Enables Full Site Takeover
A critical vulnerability in the Academy LMS plugin for WordPress is under active exploitation, allowing unauthenticated attackers to take over administrator accounts and gain full control of affected eLearning platforms. The flaw, tracked as CVE-2025-15521, carries a CVSS score of 9.8 and affects all versions of the