CVE-2026-86449: CWE-200 Information Exposure in LearnPress
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.
AI Analysis
Technical Summary
CVE-2026-86449 is an information exposure vulnerability in the LearnPress WordPress plugin prior to version 4.4.7. The issue arises because the plugin does not check user permissions before processing a user-supplied post status filter in one of its REST API endpoints. Consequently, unauthenticated attackers can enumerate courses that are not publicly published, including those in draft, pending, private, scheduled, and trashed states.
Potential Impact
Unauthenticated attackers can access information about unpublished courses that should normally be restricted. This could lead to unintended disclosure of course content or metadata that is not yet meant for public viewing. There is no indication of further exploitation such as modification or deletion of content.
Mitigation Recommendations
Upgrade LearnPress to version 4.4.7 or later, where this vulnerability has been fixed. No other mitigation is indicated or necessary once the plugin is updated.
CVE-2026-86449: CWE-200 Information Exposure in LearnPress
Description
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.
Affected software
LearnPress
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86449 is an information exposure vulnerability in the LearnPress WordPress plugin prior to version 4.4.7. The issue arises because the plugin does not check user permissions before processing a user-supplied post status filter in one of its REST API endpoints. Consequently, unauthenticated attackers can enumerate courses that are not publicly published, including those in draft, pending, private, scheduled, and trashed states.
Potential Impact
Unauthenticated attackers can access information about unpublished courses that should normally be restricted. This could lead to unintended disclosure of course content or metadata that is not yet meant for public viewing. There is no indication of further exploitation such as modification or deletion of content.
Mitigation Recommendations
Upgrade LearnPress to version 4.4.7 or later, where this vulnerability has been fixed. No other mitigation is indicated or necessary once the plugin is updated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-07T12:51:58.100Z
- State
- PUBLISHED
Threat ID: 6aaa32e455bf5e2cf517fb46
Added to database: 09/16/2026, 06:10:44 UTC
Last enriched: 09/16/2026, 06:18:22 UTC
Last updated: 09/17/2026, 00:36:17 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.