{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93882","assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","state":"PUBLISHED","assignerShortName":"Wordfence","dateReserved":"2026-09-18T20:07:37.340Z","datePublished":"2026-10-01T07:40:22.847Z","dateUpdated":"2026-10-03T15:42:52.360Z"},"containers":{"cna":{"providerMetadata":{"orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence","dateUpdated":"2026-10-01T07:40:22.847Z"},"affected":[{"vendor":"thimpress","product":"LearnPress – WordPress LMS Plugin for Create and Sell Online Courses","versions":[{"version":"0","status":"affected","lessThanOrEqual":"4.4.8","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the render_material_items() handler decides authorization against one attacker-supplied identifier (course_id) while fetching the returned material rows via a second, independently attacker-supplied identifier (item_id) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file."}],"title":"LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter","references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f35f646-1bd6-4785-bdc2-c815644b2b2d?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.7/inc/TemplateHooks/Course/CourseMaterialTemplate.php#L143"},{"url":"https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.7/inc/TemplateHooks/Course/CourseMaterialTemplate.php#L113"},{"url":"https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.7/inc/Ajax/LoadContentViaAjax.php#L25"},{"url":"https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.7/inc/Ajax/AbstractAjax.php#L31"},{"url":"https://plugins.trac.wordpress.org/browser/learnpress/tags/4.4.7/inc/Databases/class-lp-material-db.php#L92"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-639 Authorization Bypass Through User-Controlled Key","cweId":"CWE-639","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH"}}],"credits":[{"lang":"en","type":"finder","value":"Khoa Dang"}],"timeline":[{"time":"2026-09-18T20:22:41.000Z","lang":"en","value":"Vendor Notified"},{"time":"2026-09-30T19:10:55.000Z","lang":"en","value":"Disclosed"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-93882","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-10-03T15:35:30.930620Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-03T15:42:52.360Z"}}]}}