Impact
The LearnPress plugin suffers from an insecure direct object reference flaw that lets a user control a key used to identify protected resources. By manipulating this key an attacker can access or modify course content, user progress, or other sensitive information they should not be able to view. The weakness is a classic access control failure, designated as CWE-639, and results in an authorization bypass rather than arbitrary code execution or denial of service.
Affected Systems
The flaw is present in all ThimPress LearnPress WordPress plugin releases up through version 4.4.9. Sites that have not upgraded beyond this point may be exposing course material and related data to users without sufficient privileges or to unauthenticated visitors.
Risk and Exploitability
The CVSS score of 5.3 puts the vulnerability in the moderate severity range. With no EPSS data available and the vulnerability not listed in the CISA KEV catalog, there is no evidence of active exploitation at this time. Attackers would most likely exploit the flaw by sending crafted web requests that include an unauthorized key, exploiting the plugin’s missing access control checks.
OpenCVE Enrichment