Executive brief
LearnPress is a WordPress plugin used to create and manage online courses. The plugin fails to properly check user permissions in its course administration tool, allowing unauthenticated attackers to view sensitive information about enrolled students—including names, user IDs, and email addresses—without any login required. This exposure compromises student privacy and can facilitate targeted attacks or spam campaigns.
Technical details
The vulnerability exists in LearnPress's load_content_via_ajax handler, which lacks capability checks before returning course enrollment data and search functionality. An unauthenticated attacker can craft requests to the affected administrative tool to enumerate all enrolled students' display names and user identifiers for a given course, and can leverage the same handler's search filter to recover email addresses. The root cause is missing authorization validation in a WordPress AJAX endpoint. No authentication or special privileges are required to trigger the issue—the endpoint is reachable over the network from an unauthenticated state. The vulnerability was patched in version 4.4.7.
Affected products
- LearnPress LearnPress before 4.4.7
Timeline
- 2026-09-14: disclosed
- 2026-09-16: patched: Version 4.4.7 includes the fix
- 2026-09-16: advisory