REST API Vulnerability in LearnPress WordPress Plugin
CVE-2026-86449

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-86449?

The LearnPress WordPress plugin prior to version 4.4.7 contains a significant flaw in its REST API functionality. The plugin fails to adequately verify user permissions before applying a filter based on user-supplied post statuses. This oversight enables unauthenticated attackers to exploit the REST routes, gaining unauthorized visibility into unpublished courses, including drafts, private listings, and those marked as scheduled or trashed. Consequently, sensitive course information may be revealed, posing a threat to data confidentiality.

Affected Version(s)

LearnPress 4.2.7.1 < 4.4.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sai Praneeth Koti
WPScan
.