CVE-2026-93882: LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::rendermaterialitems() callback exposed on the public lp-ajax-handle (loadcontentviaajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and performs no capability check, and the rendermaterialitems() handler decides authorization against one attacker-supplied identifier (courseid) while fetching the returned material rows via a second, independently attacker-supplied identifier (itemid) with no check that the lesson belongs to the authorized course. This makes it possible for unauthenticated attackers to read and download course-material files (uploaded and external file paths/URLs) belonging to lessons in paid or enrollment-required courses, provided any single course on the site has 'No Required Enroll' enabled and owns at least one material file.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to unauthenticated material disclosure?
Affected sites must run LearnPress version 4.4.8 or earlier and have at least one course with “No Required Enroll” enabled that contains a material file. The disclosed materials can belong to lessons in paid or enrollment-required courses.
What does an attacker need to exploit this issue?
No authentication, nonce, or elevated capability is required. An attacker must supply a course_id for a qualifying no-enrollment-required course and an item_id for a lesson whose material they want to retrieve.
How can administrators assess whether their configuration is exploitable?
Check whether the site uses LearnPress 4.4.8 or earlier, then identify any course configured with “No Required Enroll” enabled that has at least one material file. If that condition exists, the public load_content_via_ajax endpoint can be used to retrieve material rows for independently selected lesson item_id values.
What content may be exposed?
Unauthenticated attackers may read and download course-material files, including uploaded files and external file paths or URLs. Materials associated with paid or enrollment-required courses may be accessible.