CVE-2026-12976 PUBLISHED

LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant

Assigner: WPScan
Reserved: 23.06.2026 Published: 12.08.2026 Updated: 12.08.2026

The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.

Product Status

Vendor Unknown
Product LearnPress
Versions Default: unaffected
  • affected from 0 to 4.4.4 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE