/Vulnerability Library

LearnPress < 4.2.7.4 - Course Material - Information Disclosure

CVE-2024-11868
Verified

Description

LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by insecure handling in class-lp-rest-material-controller.php, letting unauthenticated attackers extract paid course material, exploit requires no authentication.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

learnpress

Published Date

February 7, 2026

Template Author

pussycat0x

CVE-2024-11868.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2024-11868
CWE ID:
cwe-284

References

https://wpscan.com/vulnerability/7524ffd8-3506-48f7-89b6-d07b40533756/8

Remediation Steps

Update to the latest version beyond 4.2.7.3 or apply security patches provided by the vendor.