Description
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.
Published: 2026-08-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LearnPress WordPress plugin fails to verify that a user is enrolled in a course before processing AI‑assistant requests against that course’s lesson content. As a result, any authenticated user—including a subscriber who has not paid for the course—can request AI assistance and retrieve the protected lesson material. This lack of an access control check allows unauthorized disclosure of course content to users who have not purchased or enrolled.

Affected Systems

All installations of the LearnPress plugin with a version prior to 4.4.4 are impacted, regardless of the hosting WordPress site or other plugins. Sites must examine their LearnPress version and apply the fix if the version is below 4.4.4.

Risk and Exploitability

The vulnerability requires an authenticated user to exist, which is common in many sites. An attacker who has normal user credentials could simply enable the AI assistant request to gain restricted content. Without an enforced enrollment check, the condition for exploitation is easily met. The CVSS score is 6.5, and the EPSS score is < 1%, indicating a moderate severity and low probability of exploitation, while the risk remains driven by the required authenticated access and potential for confidential material disclosure. The flaw is not listed in CISA’s KEV catalog. Users should treat this as a medium‑to‑high risk if the AI assistant feature is enabled on a site that serves paid or protected courses.

Generated by OpenCVE AI on August 13, 2026 at 02:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LearnPress to version 4.4.4 or later, which includes an enrollment verification check for AI‑assistant requests.
  • Validate that the AI‑assistant endpoint now enforces enrollment before returning lesson content; adjust access controls if needed.
  • If an upgrade cannot be applied immediately, disable the AI‑assistant feature or restrict its availability to administrators or users with confirmed enrollment.

Generated by OpenCVE AI on August 13, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Learnpress
Learnpress learnpress
Wordpress
Wordpress wordpress
Vendors & Products Learnpress
Learnpress learnpress
Wordpress
Wordpress wordpress

Wed, 12 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.
Title LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant
References

Subscriptions

Learnpress Learnpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T19:27:38.192Z

Reserved: 2026-06-23T10:53:48.243Z

Link: CVE-2026-12976

cve-icon Vulnrichment

Updated: 2026-08-12T19:27:31.325Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T06:17:09.410

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-12976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor