Insecure Direct Object Reference in LearnPress WordPress LMS Plugin
CVE-2026-93882
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-93882?
The LearnPress LMS Plugin for WordPress exhibits a vulnerability that allows unauthorized users to access sensitive course materials. Through an insecure endpoint, attackers can maliciously manipulate parameters to access material files associated with paid courses, provided any course on the site has 'No Required Enroll' enabled. This vulnerability arises from insufficient authorization checks, making it easier for attackers to exploit the system without needing to enroll in a course. As a result, course material that should be protected can be accessed and downloaded by individuals without appropriate permissions.
Affected Version(s)
LearnPress β WordPress LMS Plugin for Create and Sell Online Courses 0 <= 4.4.8