Junglewise Threat Intelligence

CVE-2026-86449: LearnPress unauthenticated information disclosure in REST API

CVE-2026-86449 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Executive brief

LearnPress is a WordPress plugin for creating and managing online courses. An unauthenticated attacker can exploit a flaw in the REST API to view unpublished courses (drafts, pending, private, scheduled, and trashed), exposing course content that should only be visible to administrators or when formally published. This allows competitors or other malicious actors to access confidential course material before it is released.

Technical details

The vulnerability is an authorization bypass in a REST API route that applies user-supplied post status filters without verifying the requester's capabilities. An unauthenticated attacker can craft a REST request with a custom post status parameter to retrieve courses that should be restricted by WordPress access controls (draft, pending, private, scheduled, trashed). The flaw affects all versions before 4.4.7. No preconditions such as authentication or user interaction are required; the attacker simply needs network access to the WordPress site's REST API endpoint. The fix is available in LearnPress version 4.4.7 and later.

Affected products

  • LearnPress LearnPress before 4.4.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in version 4.4.7

References