Executive brief
LearnPress is a popular WordPress plugin for creating online learning platforms. A flaw in the Sepay Payment add-on allows attackers to retrieve the payment status of any order on the site without authentication, simply by guessing sequential order numbers. This exposes sensitive financial transaction data that should be restricted to authorized users only.
Technical details
The LearnPress Sepay Payment plugin fails to perform authorization checks on a REST API endpoint that exposes order payment status. The vulnerability is in the /wp-json/learnpress-sepay/v1/lp-order endpoint, which accepts an order_id parameter and returns the order status without verifying the requester's identity or permissions. Since WordPress order IDs are sequential post IDs, an attacker can enumerate all orders on a site by iterating through ID ranges. The endpoint is network-reachable and requires no authentication, credentials, or user interaction to exploit. This vulnerability affects versions up to and including 4.0.2; a patch is available in version 4.0.3 or later.
Affected products
- LearnPress Sepay Payment before 4.0.3
Timeline
- 2026-08-25: disclosed
- 2026-08-27: patched: Fixed in version 4.0.3