CVE-2026-12976
Deferred Deferred - Pending Action

AI-Assistant Lesson Content Exposure in LearnPress

Vulnerability report for CVE-2026-12976, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thimpress learnpress to 4.4.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The LearnPress WordPress plugin before version 4.4.4 has a vulnerability where it does not check if a user is enrolled in a course before allowing AI-assistant requests to access lesson content. This means any authenticated user, including subscribers, can view paid course materials without paying.

Detection Guidance

Check the installed version of the LearnPress plugin in your WordPress admin panel. If it is below 4.4.4, the system is vulnerable. You can also use WPScan to detect the plugin version remotely with: wpscan --url <target-url> --enumerate vp,vt.

Impact Analysis

If you use the LearnPress plugin before 4.4.4, attackers could access paid course content without enrollment. This could lead to unauthorized access to sensitive or proprietary material, undermining the plugin's intended access controls.

Compliance Impact

This vulnerability could expose sensitive course content, potentially violating data protection regulations like GDPR or HIPAA if the content includes personal or confidential information. Unauthorized access may lead to compliance breaches.

Mitigation Strategies

Update the LearnPress plugin to version 4.4.4 or later immediately. If updating is not possible, disable the AI Assistant feature in the plugin settings or restrict access to untrusted users until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12976. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart