Impact
The LearnPress WordPress plugin fails to verify that a user is enrolled in a course before processing AI‑assistant requests against that course’s lesson content. As a result, any authenticated user—including a subscriber who has not paid for the course—can request AI assistance and retrieve the protected lesson material. This lack of an access control check allows unauthorized disclosure of course content to users who have not purchased or enrolled.
Affected Systems
All installations of the LearnPress plugin with a version prior to 4.4.4 are impacted, regardless of the hosting WordPress site or other plugins. Sites must examine their LearnPress version and apply the fix if the version is below 4.4.4.
Risk and Exploitability
The vulnerability requires an authenticated user to exist, which is common in many sites. An attacker who has normal user credentials could simply enable the AI assistant request to gain restricted content. Without an enforced enrollment check, the condition for exploitation is easily met. Exact CVSS or EPSS scores are not provided; the risk is therefore scored by the required authenticated access and the potential for confidential material disclosure. The flaw is not listed in CISA’s KEV catalog. Users should treat this as a medium‑to‑high risk if the AI assistant feature is enabled on a site that serves paid or protected courses.
OpenCVE Enrichment