cleantalk
Vulnerabilities and Security Researches

LearnPress – WordPress LMS Plugin, CVE-2026-86449

CVE, Research URL

CVE-2026-86449

Published on
Sep 16, 2026
Research Description
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.
Affected versions
max 4.4.7.
Status
vulnerable