REST API Vulnerability in LearnPress WordPress Plugin
CVE-2026-86449
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-86449?
The LearnPress WordPress plugin prior to version 4.4.7 contains a significant flaw in its REST API functionality. The plugin fails to adequately verify user permissions before applying a filter based on user-supplied post statuses. This oversight enables unauthenticated attackers to exploit the REST routes, gaining unauthorized visibility into unpublished courses, including drafts, private listings, and those marked as scheduled or trashed. Consequently, sensitive course information may be revealed, posing a threat to data confidentiality.
Affected Version(s)
LearnPress 4.2.7.1 < 4.4.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.