A vulnerability classified as problematic was found in Academy LMS Plugin up to 3.8.2 on WordPress. Affected by this issue is some unknown functionality of the component REST API. The manipulation results in improper access controls.
This vulnerability was named CVE-2026-16563. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.