Junglewise Threat Intelligence

CVE-2026-7566: LearnPress Backup & Migration Tool PHP Object Injection

CVE-2026-7566 · Severity: medium · CVSS 6.6 · Published 2026-06-06

Executive brief

The LearnPress Backup & Migration Tool, a WordPress plugin used for moving website data, contains a security flaw that could allow an administrator to execute unauthorized commands. While the vulnerability requires high-level access to exploit, it could lead to the deletion of files or theft of sensitive data if other vulnerable components are present on the site. Users should update to a version newer than 4.1.4 to mitigate this risk.

Technical details

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection via the deserialization of untrusted input in versions up to 4.1.4. This vulnerability (CWE-502) allows authenticated attackers with administrator-level privileges to inject a PHP Object. While the plugin itself does not contain a known POP chain, the vulnerability can be weaponized if another installed plugin or theme provides a suitable chain. Successful exploitation could lead to arbitrary file deletion, sensitive data retrieval, or remote code execution depending on the available POP chain. The issue appears to be addressed in version 4.1.5.

Affected products

  • LearnPress LearnPress – Backup & Migration Tool Up to, and including, 4.1.4

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: advisory

References

Related threats