Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server.
This issue affects Academy LMS Pro: from n/a before 3.5.2.
This issue affects Academy LMS Pro: from n/a before 3.5.2.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update the WordPress Academy LMS Pro Plugin to the latest available version (at least 3.5.2).
Workaround
No workaround given by the vendor.
References
History
Tue, 16 Jun 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2. | |
| Title | WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-16T21:24:27.789Z
Reserved: 2026-04-07T10:48:50.116Z
Link: CVE-2026-39598
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses