CVE-2026-12976: LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12976?
CVE-2026-12976 has a risk rating of 48, indicating a moderate severity due to its potential for unauthorized access to sensitive information.
How do I fix CVE-2026-12976?
To fix CVE-2026-12976, you should update the LearnPress WordPress plugin to version 4.4.4 or later, where the vulnerability has been patched.
What type of information is exposed in CVE-2026-12976?
CVE-2026-12976 exposes sensitive information from paid course content to any authenticated user, including subscribers, who are not enrolled in those courses.
Who is affected by CVE-2026-12976?
CVE-2026-12976 affects any website using the LearnPress WordPress plugin version earlier than 4.4.4 that allows authenticated users access to course content.
Is there a workaround for CVE-2026-12976 if I can't update immediately?
As a temporary workaround for CVE-2026-12976, restrict user roles and capabilities to limit access to the AI assistant functionality until the plugin can be updated.