CVE-2026-39717: WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability
Published Oct 2, 2026
·Updated
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
Affected Software
1 affected component
thimpress LearnPress<=4.4.9.1
Event History
Oct 2, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-privileged access (PR:L). It can be exploited remotely over the network without user interaction (AV:N, UI:N), and the attack complexity is low (AC:L).
2
What security impact is indicated?
The reported impact is limited to integrity (I:L). No confidentiality or availability impact is indicated (C:N, A:N), and the scope is unchanged (S:U).
3
Which LearnPress versions are affected?
The issue affects LearnPress versions through 4.4.9.1. The provided data does not identify a fixed version.