CVE-2026-86448: LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order
Published Sep 16, 2026
·Updated
The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a previously generated order export file, allowing unauthenticated attackers who can determine its identifier to download customer names, purchases, amounts and guest email addresses.
Event History
Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What condition must exist for an installation to be exposed?
A previously generated order export file must be available, and an attacker must be able to determine its identifier. The download does not require authentication, a capability, or a nonce check.
2
What version should be deployed to address this issue?
Upgrade LearnPress to version 4.4.7 or later. Versions before 4.4.7 are affected.