CVE-2026-7565: LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
LearnPress – Backup & Migration Tool plugin for WordPressfrom your environment.Uninstall or deactivate the LearnPress – Backup & Migration Tool plugin from any affected WordPress installations until an upstream fix is available.
- Compensating control
Apply access restrictions as a temporary mitigation: limit administrator-level access to trusted IP addresses, remove or disable unnecessary administrator accounts, and limit administrative privileges to only trusted users until the plugin is fixed.
- Compensating control
Deploy WAF or web server rules to block requests attempting directory traversal or requests containing the 'import-user-file' parameter (e.g., block requests with ../ sequences or the specific parameter) to prevent arbitrary file read attempts.
- Operational
Investigate for signs of exploitation (check webserver and application logs for requests using the 'import-user-file' parameter and for accesses to sensitive files). Rotate any credentials, API keys, or secrets that may have been exposed as a result of the vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7565?
The severity of CVE-2026-7565 is classified as medium with a score of 4.9.
What type of vulnerability is CVE-2026-7565?
CVE-2026-7565 is a Path Traversal vulnerability allowing Arbitrary File Read.
Who can exploit CVE-2026-7565?
Authenticated attackers with administrator-level access can exploit CVE-2026-7565.
How do I fix CVE-2026-7565?
To fix CVE-2026-7565, update the LearnPress Backup & Migration Tool plugin to the latest version.
What is affected by CVE-2026-7565?
CVE-2026-7565 affects all versions of the LearnPress Backup & Migration Tool plugin up to and including 4.1.4.