The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents by adding/removing/updating/re-ordering sections or modifying section items.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thimpress
Thimpress learnpress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Thimpress
Thimpress learnpress Wordpress Wordpress wordpress |
Tue, 06 Jan 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents by adding/removing/updating/re-ordering sections or modifying section items. | |
| Title | LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-06T08:21:49.475Z
Updated: 2026-01-06T14:28:43.754Z
Reserved: 2025-12-03T15:01:16.691Z
Link: CVE-2025-13964
Updated: 2026-01-06T14:28:37.776Z
Status : Received
Published: 2026-01-06T09:15:54.513
Modified: 2026-01-06T09:15:54.513
Link: CVE-2025-13964
No data.