Skip to content
Threat Feed
high advisory

CVE-2026-93882 - IDOR in LearnPress WordPress LMS Plugin

An unauthenticated IDOR vulnerability in the LearnPress WordPress plugin allows unauthorized access to private course materials by manipulating the course and item identifiers in AJAX requests.

CVE search metadata

CVE search record: CVE-2026-93882. Severity: high. CVSS: 7.5. KEV: no. Product: LearnPress (<= 4.4.8). Brief: CVE-2026-93882 - IDOR in LearnPress WordPress LMS Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-learnpress-idor/

CVE-2026-93882 describes an Insecure Direct Object Reference (IDOR) vulnerability within the LearnPress WordPress plugin, impacting versions up to and including 4.4.8. The vulnerability resides in the CourseMaterialTemplate::render_material_items() callback, which is exposed through the public 'lp-ajax-handle' endpoint. This specific endpoint is included in the plugin's no-nonce allowlist and lacks necessary capability checks.

The flaw occurs because the handler performs authorization validation based solely on an attacker-supplied 'course_id', while retrieving course-material records using an independently attacker-supplied 'item_id'. By targeting a site that has at least one course with 'No Required Enroll' enabled, an unauthenticated attacker can supply the identifier of a public course to bypass initial checks and then leverage the 'item_id' parameter to retrieve, read, or download materials associated with private, paid, or enrollment-restricted courses. This exposure poses a significant risk to the confidentiality of proprietary educational content and student-accessible materials.

Attack Chain

  1. Attacker identifies a WordPress site running LearnPress version 4.4.8 or earlier.
  2. Attacker discovers the public 'lp-ajax-handle' endpoint exposed by the plugin.
  3. Attacker identifies at least one course on the target site with the 'No Required Enroll' setting enabled.
  4. Attacker crafts an AJAX request to the endpoint, setting the 'action' parameter to 'load_content_via_ajax'.
  5. Attacker provides the 'course_id' of the public course to pass the superficial authorization check within the handler.
  6. Attacker provides the 'item_id' corresponding to a private or paid resource in the target course.
  7. The vulnerable 'render_material_items()' method processes the request, ignoring the ownership check between the 'course_id' and 'item_id'.
  8. The server returns the sensitive file path or external URL for the requested private material to the attacker.

Impact

Successful exploitation allows unauthenticated users to gain unauthorized access to private and paid course materials. This results in the potential leak of proprietary intellectual property, protected digital assets, and sensitive student resources. The vulnerability affects any site utilizing LearnPress for LMS functionality where sensitive materials are stored in courses that are not intended for public access.

Recommendation

  1. Upgrade the LearnPress plugin to a version patched against CVE-2026-93882 immediately.
  2. Implement a Web Application Firewall (WAF) rule to inspect and block requests to the 'lp-ajax-handle' endpoint that contain suspicious 'item_id' parameters if a patch cannot be immediately deployed.
  3. Review access logs for high-frequency requests to the 'lp-ajax-handle' endpoint from unauthenticated users, specifically looking for variations in the 'item_id' field.
  4. Audit current LearnPress configurations to ensure that sensitive materials are not stored in courses with 'No Required Enroll' enabled until the update is applied.

Immediate actions

Upgrade LearnPress to the latest secure version beyond 4.4.8.

IT Operations 24h

Threat Hunt

Search logs for multiple 200 OK responses to lp-ajax-handle with varying item_id parameters from the same source IP.

T1190 high high confidence hunt now

Data: Web server access logs

Mitigations

Disable the plugin if patching is delayed.

immediate IT Operations

CVE-2026-93882

Detection coverage 1

Detects CVE-2026-93882 Exploitation - IDOR Attempt on LearnPress

high

Detects potential exploitation of CVE-2026-93882 via suspicious POST requests to the LearnPress AJAX handler that may indicate IDOR enumeration.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →