Description
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the render_material_items() handler decides authorization against one attacker-supplied identifier (course_id) while fetching the returned material rows via a second, independently attacker-supplied identifier (item_id) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in LearnPress up to and including version 4.4.8, where the public AJAX handler lp-ajax-handle calls render_material_items() without performing capability checks. The handler authorizes only the course_id supplied by the attacker and then retrieves material rows for an item_id supplied separately, without verifying that the item belongs to the authorized course. This allows an unauthenticated user to read and download material files—including both uploaded files and external URLs—associated with lessons in paid or enrollment‑required courses. The flaw results in exposure of potentially confidential course content to anyone who can access the endpoint.

Affected Systems

WordPress sites that have the LearnPress LMS plugin from thimpress installed and use a version up to 4.4.8. The issue affects all users of the plugin regardless of user role; the attack can be performed by any internet user who can send a request to the load_content_via_ajax endpoint.

Risk and Exploitability

The CVSS score is 7.5, indicating high severity. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a direct HTTP request to the publicly exposed Ajax endpoint with crafted course_id and item_id parameters. The attacker can exploit the flaw from any location without authentication, provided the site has at least one course with "No Required Enroll" enabled and that course contains at least one material file.

Generated by OpenCVE AI on October 1, 2026 at 10:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the LearnPress plugin to version 4.4.9 or later, which addresses the insecure direct object reference.
  • If an update is not immediately possible, restrict access to the lp-ajax-handle endpoint by applying a firewall or apply a WordPress security plugin rule to block unauthenticated requests to the load_content_via_ajax action.
  • Audit courses that have the "No Required Enroll" option enabled, remove unnecessary material files, and ensure that only authorized users can view lesson content.

Generated by OpenCVE AI on October 1, 2026 at 10:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the render_material_items() handler decides authorization against one attacker-supplied identifier (course_id) while fetching the returned material rows via a second, independently attacker-supplied identifier (item_id) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file.
Title LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T07:40:22.847Z

Reserved: 2026-09-18T20:07:37.340Z

Link: CVE-2026-93882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T08:16:53.330

Modified: 2026-10-01T12:40:28.083

Link: CVE-2026-93882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T10:15:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key