CVE-2026-86447: CWE-200 Information Exposure in LearnPress
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against the course they are enrolled on, and to recover their email addresses through the same handler's search filter.
AI Analysis
Technical Summary
CVE-2026-86447 is an information exposure vulnerability (CWE-200) in the LearnPress WordPress plugin prior to version 4.4.7. The plugin fails to verify user capabilities in one of its administrative course tools, enabling unauthenticated attackers to enumerate enrolled students' display names and user IDs associated with courses. Additionally, attackers can extract email addresses through the same handler's search functionality. This vulnerability affects versions >=4.4.6 and <4.4.7.
Potential Impact
Unauthenticated attackers can obtain personally identifiable information (PII) including display names, user identifiers, and email addresses of students enrolled in courses. This exposure can lead to privacy violations and potential targeted phishing or social engineering attacks against affected users.
Mitigation Recommendations
Upgrade LearnPress to version 4.4.7 or later, where this vulnerability is fixed. Since the vulnerability is due to missing capability checks, applying the official update will restore proper access controls and prevent unauthorized information disclosure.
CVE-2026-86447: CWE-200 Information Exposure in LearnPress
Description
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against the course they are enrolled on, and to recover their email addresses through the same handler's search filter.
Affected software
LearnPress
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86447 is an information exposure vulnerability (CWE-200) in the LearnPress WordPress plugin prior to version 4.4.7. The plugin fails to verify user capabilities in one of its administrative course tools, enabling unauthenticated attackers to enumerate enrolled students' display names and user IDs associated with courses. Additionally, attackers can extract email addresses through the same handler's search functionality. This vulnerability affects versions >=4.4.6 and <4.4.7.
Potential Impact
Unauthenticated attackers can obtain personally identifiable information (PII) including display names, user identifiers, and email addresses of students enrolled in courses. This exposure can lead to privacy violations and potential targeted phishing or social engineering attacks against affected users.
Mitigation Recommendations
Upgrade LearnPress to version 4.4.7 or later, where this vulnerability is fixed. Since the vulnerability is due to missing capability checks, applying the official update will restore proper access controls and prevent unauthorized information disclosure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-07T12:51:53.650Z
- State
- PUBLISHED
Threat ID: 6aaa32e255bf5e2cf517fb3d
Added to database: 09/16/2026, 06:10:42 UTC
Last enriched: 09/16/2026, 06:18:33 UTC
Last updated: 09/17/2026, 01:16:11 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.