Unauthorized Modification in LearnPress Plugin for WordPress
CVE-2026-75982

4.4MEDIUM

What is CVE-2026-75982?

The LearnPress plugin for WordPress allows authenticated attackers with Editor-level access and above to exploit a flaw in the learnpress_create_page AJAX action. By leveraging insufficient validation, attackers can modify arbitrary WordPress options, such as enabling public registration or corrupting active plugin settings, thereby compromising the site's integrity and functionality.

Affected Version(s)

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 0 <= 4.4.4

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.