Sensitive Information Exposure in LearnPress Plugin for WordPress
CVE-2025-14798

5.3MEDIUM

What is CVE-2025-14798?

The LearnPress WordPress LMS Plugin is susceptible to a vulnerability that enables unauthenticated attackers to access sensitive user information. This includes personal details such as first names, last names, and links to social profiles, as well as enrollment data. The issue arises from flaws in the get_item_permissions_check function within versions up to and including 4.3.2.4, highlighting the importance of timely updates and rigorous security measures to protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses * <= 4.3.2.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andrea bocchetti
.