Impact
The LearnPress WordPress plugin, prior to version 4.4.7, fails to verify a user's capabilities before applying a user supplied post status filter in a REST route. This oversight allows an unauthenticated attacker to enumerate courses that are not publicly visible, including those in draft, pending, private, scheduled, and trashed states. The primary impact is the exposure of sensitive or confidential course content to anyone who can access the plugin's API endpoint, potentially leaking intellectual property or personal data stored in course materials. This is a classic access control flaw that permits information disclosure without authorization, falling under CWE-200.
Affected Systems
LearnPress plugin for WordPress installations using any version before 4.4.7. No specific WordPress core or other product versions are cited; the vulnerability is confined to the LearnPress plugin code itself.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in CISA KEV. The CVSS score of 5.3 suggests moderate severity. The capability to reach the REST API endpoint without authentication means an attacker can easily request unpublished course listings. The likely attack vector is through the public REST API endpoint exposed by LearnPress, which accepts a status filter and returns course data across various non‑public states. Exploit conditions are minimal: a simple HTTP request to the vulnerable endpoint with a status parameter suffices to harvest sensitive course content.
OpenCVE Enrichment