Executive brief
LearnPress is a popular WordPress plugin used to create and sell online courses. A security flaw allows registered users to bypass the payment process and enroll in any paid course for free. By manipulating the course quantity during the checkout process, an attacker can force the total price to zero, resulting in a loss of revenue and unauthorized access to premium content.
Technical details
The LearnPress plugin (up to version 4.3.5) is vulnerable to an authorization bypass (CWE-639) due to improper handling of user-supplied parameters in its REST API endpoint. Specifically, the REST API passes unsanitized input to the add_to_cart() function, where an array_merge() call allows user-controlled values to overwrite hardcoded defaults. An authenticated attacker with subscriber-level permissions can exploit this by submitting a quantity value of zero. This causes the internal order calculation to result in a $0 total, effectively bypassing payment gateway requirements and granting free access to paid courses.
Affected products
- LearnPress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Up to and including 4.3.5
Timeline
- 2026-05-14: disclosed: CVE published by Wordfence/NVD
References
- https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.3/inc/cart/class-lp-cart.php
- https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.3/inc/cart/class-lp-cart.php
- https://plugins.trac.wordpress.org/browser/learnpress/tags/4.3.3/inc/rest-api/v1/frontend/class-lp-rest-courses-controller.php
- https://plugins.trac.wordpress.org/browser/learnpress/trunk/inc/cart/class-lp-cart.php
- https://plugins.trac.wordpress.org/browser/learnpress/trunk/inc/cart/class-lp-cart.php
- https://plugins.trac.wordpress.org/browser/learnpress/trunk/inc/rest-api/v1/frontend/class-lp-rest-courses-controller.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3521636%40learnpress&new=3521636%40learnpress&sfp_email=&sfph_mail=