A vulnerability identified as critical has been detected in Kodezen Academy LMS Pro Plugin up to 3.5.1 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes unrestricted upload.

The identification of this vulnerability is CVE-2026-39598. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.