Description
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects LearnPress: from n/a through 4.4.9.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass via Insecure Direct Object References
Action: Immediate Patch
AI Analysis

Impact

The LearnPress plugin suffers from an insecure direct object reference flaw that lets a user control a key used to identify protected resources. By manipulating this key an attacker can access or modify course content, user progress, or other sensitive information they should not be able to view. The weakness is a classic access control failure, designated as CWE-639, and results in an authorization bypass rather than arbitrary code execution or denial of service.

Affected Systems

The flaw is present in all ThimPress LearnPress WordPress plugin releases up through version 4.4.9. Sites that have not upgraded beyond this point may be exposing course material and related data to users without sufficient privileges or to unauthenticated visitors.

Risk and Exploitability

The CVSS score of 5.3 puts the vulnerability in the moderate severity range. With no EPSS data available and the vulnerability not listed in the CISA KEV catalog, there is no evidence of active exploitation at this time. Attackers would most likely exploit the flaw by sending crafted web requests that include an unauthorized key, exploiting the plugin’s missing access control checks.

Generated by OpenCVE AI on October 2, 2026 at 12:30 UTC.

Remediation

Vendor Solution

Update the WordPress LearnPress plugin to the latest available version (at least 4.4.9.1).


OpenCVE Recommended Actions

  • Update the LearnPress plugin to version 4.4.9.1 or newer.
  • Adjust LearnPress user role permissions to limit who can access or modify course materials, ensuring that only roles with legitimate business need have such rights.
  • Monitor site logs for suspicious access attempts to protected course content during the migration period.

Generated by OpenCVE AI on October 2, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.
Title WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-02T09:56:47.782Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104403

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:06.947

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-104403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:30:20Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key