CVE-2026-93882: LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter

Published Oct 1, 2026
·
Updated

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::rendermaterialitems() callback exposed on the public lp-ajax-handle (loadcontentviaajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the rendermaterialitems() handler decides authorization against one attacker-supplied identifier (courseid) while fetching the returned material rows via a second, independently attacker-supplied identifier (itemid) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file.

Affected Software

1 affected component
thimpress LearnPress<=4.4.8

Event History

Oct 1, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to unauthenticated material disclosure?

Affected sites must run LearnPress version 4.4.8 or earlier and have at least one course with “No Required Enroll” enabled that contains a material file. The disclosed materials can belong to lessons in paid or enrollment-required courses.

2

What does an attacker need to exploit this issue?

No authentication, nonce, or elevated capability is required. An attacker must supply a course_id for a qualifying no-enrollment-required course and an item_id for a lesson whose material they want to retrieve.

3

How can administrators assess whether their configuration is exploitable?

Check whether the site uses LearnPress 4.4.8 or earlier, then identify any course configured with “No Required Enroll” enabled that has at least one material file. If that condition exists, the public load_content_via_ajax endpoint can be used to retrieve material rows for independently selected lesson item_id values.

4

What content may be exposed?

Unauthenticated attackers may read and download course-material files, including uploaded files and external file paths or URLs. Materials associated with paid or enrollment-required courses may be accessible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203