CVE-2026-8383: LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API
The LearnPress WordPress plugin before 4.3.7 does not gate the edit context on one of its REST endpoint behind the editusers capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LearnPress (WordPress plugin)to a version that resolves this vulnerability.Fixed in 4.3.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8383?
The severity of CVE-2026-8383 is classified as medium with a score of 5.3.
How do I fix CVE-2026-8383?
To fix CVE-2026-8383, update the LearnPress plugin to version 4.3.7 or later.
What type of information is disclosed in CVE-2026-8383?
CVE-2026-8383 allows unauthenticated users to retrieve sensitive information such as user roles, capabilities, locale, and registration dates.
Is CVE-2026-8383 exploitable without authentication?
Yes, CVE-2026-8383 can be exploited by unauthenticated visitors accessing the REST API.
What plugin is affected by CVE-2026-8383?
The LearnPress WordPress plugin is affected by CVE-2026-8383.