What the vulnerability does
01Description
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course material.
Explanation of Vulnerability in Simple Terms
02Summary
LearnPress versions up to 4.2.7.3 contain an access control flaw that allows unauthenticated attackers to read sensitive information. The plugin fails to properly restrict access to certain data, exposing information that should be protected. No user interaction is required to exploit this vulnerability. Site administrators should update to a version newer than 4.2.7.3.
What an attacker can do
03Attacker Capabilities
Read sensitive information without authentication.
Potential impact on your site
04Site Impact
Unauthorized users can access protected course or student data stored in your LearnPress installation.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 10, 2024
CVE published
April 8, 2026
Record updated