CVE-2025-11372: LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permissioncallback set to returntrue. This makes it possible for unauthenticated attackers to perform destructive database operations including dropping indexes on any table (including WordPress core tables like wpoptions), creating duplicate configuration entries, and degrading site performance via the /wp-json/lp/v1/admin/tools/create-indexs endpoint granted they can provide table names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11372?
CVE-2025-11372 is classified as a critical vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2025-11372?
To fix CVE-2025-11372, update the LearnPress – WordPress LMS Plugin to version 4.2.9.3 or later.
Which versions of LearnPress are affected by CVE-2025-11372?
CVE-2025-11372 affects all versions of the LearnPress – WordPress LMS Plugin up to and including version 4.2.9.2.
What type of vulnerability is CVE-2025-11372?
CVE-2025-11372 is a data modification vulnerability resulting from insufficient capability checks on REST API endpoints.
Who is impacted by CVE-2025-11372?
Users of the LearnPress – WordPress LMS Plugin who are on affected versions are at risk due to CVE-2025-11372.