CVE-2026-104403: WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 2, 2026
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects LearnPress: from n/a through 4.4.9.
Affected Software
1 affected component
thimpress LearnPress<=4.4.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LearnPress pluginto a version that resolves this vulnerability.Fixed in 4.4.9.1
Event History
Oct 2, 2026
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which LearnPress versions are affected?
The issue affects ThimPress LearnPress versions through 4.4.9. The earliest affected version is not specified.
2
Does an attacker need an account or user interaction to exploit this issue?
No. The CVSS vector indicates network-based exploitation with no privileges required and no user interaction.
3
What is the expected security impact?
The CVSS vector indicates low confidentiality impact, with no integrity or availability impact identified.