LearnPress < 4.2.7.4 - Course Material - Information Disclosure
CVE-2024-11868
Verified
Description
LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by insecure handling in class-lp-rest-material-controller.php, letting unauthenticated attackers extract paid course material, exploit requires no authentication.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Affected Product
learnpress
Published Date
February 7, 2026
Template Author
pussycat0x
CVE-2024-11868.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2024-11868
CWE ID:
cwe-284
Remediation Steps
Update to the latest version beyond 4.2.7.3 or apply security patches provided by the vendor.