PatchSiren

LearnPress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW LearnPress CVE published 2026-09-17

CVE-2026-86446

CVE-2026-86446 LearnPress WordPress plugin vulnerability allows unauthenticated attackers to obtain correct quiz answers and instructor explanations without enrolling in courses. This issue arises from the plugin's failure to restrict correctness flags for quiz answers, potentially impacting course integrity and confidentiality. Defenders should verify and restrict access to course content, especially for [truncated]

LOW LearnPress CVE published 2026-08-10

CVE-2026-12971

The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery. This vulnerability allows users with instructor roles to potentially induce the server to make requests to external hosts, which could lea [truncated]

HIGH LearnPress CVE published 2026-07-20

CVE-2026-12970

CVE-2026-12970 is a Reflected Cross-Site Scripting vulnerability in LearnPress WordPress plugin before 4.4.1. The plugin does not escape a search parameter before reflecting it into an HTML attribute, potentially allowing attackers to inject malicious scripts. This vulnerability executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link. Users should revi [truncated]

MEDIUM LearnPress CVE published 2026-06-17

CVE-2026-8383

The LearnPress WordPress plugin before 4.3.7 has a vulnerability allowing unauthenticated visitors to retrieve user roles, capabilities, and other sensitive information via a crafted request to a REST endpoint. This issue arises from the plugin's failure to properly gate the 'edit' context on one of its REST endpoints behind the 'edit_users' capability. As a result, attackers can exploit this vulnerabilit [truncated]