Sensitive Information Exposure in LearnPress Plugin for WordPress
CVE-2025-14798
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2025-14798?
The LearnPress WordPress LMS Plugin is susceptible to a vulnerability that enables unauthenticated attackers to access sensitive user information. This includes personal details such as first names, last names, and links to social profiles, as well as enrollment data. The issue arises from flaws in the get_item_permissions_check function within versions up to and including 4.3.2.4, highlighting the importance of timely updates and rigorous security measures to protect user data.
Affected Version(s)
LearnPress β WordPress LMS Plugin for Create and Sell Online Courses 0 <= 4.3.2.4