CVE-2026-93882
Received Received - Intake

Insecure Direct Object Reference in LearnPress WordPress LMS Plugin

Vulnerability report for CVE-2026-93882, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the render_material_items() handler decides authorization against one attacker-supplied identifier (course_id) while fetching the returned material rows via a second, independently attacker-supplied identifier (item_id) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thimpress learnpress to 4.4.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the LearnPress WordPress LMS plugin. It allows unauthenticated attackers to access and download course materials from lessons in paid or enrollment-required courses by exploiting improper authorization checks. The flaw exists in the CourseMaterialTemplate::render_material_items() function, which uses two user-supplied identifiers (course_id and item_id) without verifying if the lesson belongs to the authorized course.

The vulnerability is exposed via the public lp-ajax-handle (load_content_via_ajax) endpoint, which is explicitly allowed in the AbstractAjax no-nonce allowlist and performs no capability checks.

Detection Guidance

Check for unauthorized access to course materials via the lp-ajax-handle endpoint. Monitor logs for requests to /wp-admin/admin-ajax.php with the action parameter set to load_content_via_ajax and parameters course_id and item_id. Use tools like curl to test the endpoint manually: curl -X POST 'http://example.com/wp-admin/admin-ajax.php' -d 'action=load_content_via_ajax&course_id=1&item_id=1'

Inspect WordPress plugin versions. If LearnPress is installed, verify if it is version 4.4.8 or lower. Commands: wp plugin list | grep learnpress or grep -r 'LearnPress' /var/www/html/wp-content/plugins/

Impact Analysis

If you use the LearnPress plugin, attackers could exploit this to access and download course materials from lessons in paid or restricted courses without proper authorization. This could lead to unauthorized access to sensitive or proprietary content, financial loss if paid courses are accessed without payment, and potential reputational damage to your organization or platform.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR if personal or sensitive data in course materials is exposed without authorization. For HIPAA, if course materials contain protected health information (PHI) and are accessed improperly, it could violate patient privacy requirements. Organizations may face legal penalties, fines, or reputational harm due to unauthorized data exposure.

Mitigation Strategies

Update the LearnPress plugin to the latest version immediately. If an update is not available, disable the plugin temporarily until a patch is released. Restrict access to the admin-ajax.php endpoint by implementing firewall rules or server-side restrictions.

Review and remove any exposed course materials. Audit user permissions and disable guest access to sensitive courses. Monitor for any signs of exploitation in server logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93882. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart