CVE-2025-12098: Academylms Academy Lms Pro

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.8 via the 'enqueue_social_login_script' function. This makes it possible for unauthenticated attackers to extract sensitive data including the Facebook App Secret if Facebook Social Login is enabled.

Affected products

  • Academylms Academy Lms Pro: up to and including 3.3.8

Published 2025-11-08. Last modified 2026-10-07.