Junglewise Threat Intelligence

CVE-2026-7565: LearnPress Backup & Migration Tool directory traversal in import-user-file

CVE-2026-7565 · Severity: medium · CVSS 4.9 · Published 2026-06-06

Executive brief

The LearnPress Backup & Migration Tool, a WordPress plugin used for managing site data, contains a security flaw that allows administrators to access files they should not be able to see. By exploiting this vulnerability, an authorized user with high-level permissions could read sensitive configuration files or system data from the web server. This could lead to the exposure of credentials or other private information stored on the hosting environment.

Technical details

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to arbitrary file reading due to improper path validation in the 'import-user-file' parameter. This directory traversal vulnerability (CWE-22) allows authenticated attackers with administrator-level privileges to bypass intended directory restrictions. By supplying specially crafted paths, an attacker can read the contents of sensitive files on the server. The issue exists in the class-lp-import-user-data.php component and is addressed in versions following 4.1.4.

Affected products

  • LearnPress LearnPress – Backup & Migration Tool up to, and including, 4.1.4

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: advisory

References

Related threats