Impact
The vulnerability resides in LearnPress up to and including version 4.4.8, where the public AJAX handler lp-ajax-handle calls render_material_items() without performing capability checks. The handler authorizes only the course_id supplied by the attacker and then retrieves material rows for an item_id supplied separately, without verifying that the item belongs to the authorized course. This allows an unauthenticated user to read and download material files—including both uploaded files and external URLs—associated with lessons in paid or enrollment‑required courses. The flaw results in exposure of potentially confidential course content to anyone who can access the endpoint.
Affected Systems
WordPress sites that have the LearnPress LMS plugin from thimpress installed and use a version up to 4.4.8. The issue affects all users of the plugin regardless of user role; the attack can be performed by any internet user who can send a request to the load_content_via_ajax endpoint.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a direct HTTP request to the publicly exposed Ajax endpoint with crafted course_id and item_id parameters. The attacker can exploit the flaw from any location without authentication, provided the site has at least one course with "No Required Enroll" enabled and that course contains at least one material file.
OpenCVE Enrichment