{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3athimpresslearnpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93882"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LearnPress (\u003c= 4.4.8)"],"_cs_severities":["high"],"_cs_tags":["idor","wordpress","lms","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["ThimPress"],"content_html":"\u003cp\u003eCVE-2026-93882 describes an Insecure Direct Object Reference (IDOR) vulnerability within the LearnPress WordPress plugin, impacting versions up to and including 4.4.8. The vulnerability resides in the CourseMaterialTemplate::render_material_items() callback, which is exposed through the public 'lp-ajax-handle' endpoint. This specific endpoint is included in the plugin's no-nonce allowlist and lacks necessary capability checks.\u003c/p\u003e\n\u003cp\u003eThe flaw occurs because the handler performs authorization validation based solely on an attacker-supplied 'course_id', while retrieving course-material records using an independently attacker-supplied 'item_id'. By targeting a site that has at least one course with 'No Required Enroll' enabled, an unauthenticated attacker can supply the identifier of a public course to bypass initial checks and then leverage the 'item_id' parameter to retrieve, read, or download materials associated with private, paid, or enrollment-restricted courses. This exposure poses a significant risk to the confidentiality of proprietary educational content and student-accessible materials.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running LearnPress version 4.4.8 or earlier.\u003c/li\u003e\n\u003cli\u003eAttacker discovers the public 'lp-ajax-handle' endpoint exposed by the plugin.\u003c/li\u003e\n\u003cli\u003eAttacker identifies at least one course on the target site with the 'No Required Enroll' setting enabled.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an AJAX request to the endpoint, setting the 'action' parameter to 'load_content_via_ajax'.\u003c/li\u003e\n\u003cli\u003eAttacker provides the 'course_id' of the public course to pass the superficial authorization check within the handler.\u003c/li\u003e\n\u003cli\u003eAttacker provides the 'item_id' corresponding to a private or paid resource in the target course.\u003c/li\u003e\n\u003cli\u003eThe vulnerable 'render_material_items()' method processes the request, ignoring the ownership check between the 'course_id' and 'item_id'.\u003c/li\u003e\n\u003cli\u003eThe server returns the sensitive file path or external URL for the requested private material to the attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated users to gain unauthorized access to private and paid course materials. This results in the potential leak of proprietary intellectual property, protected digital assets, and sensitive student resources. The vulnerability affects any site utilizing LearnPress for LMS functionality where sensitive materials are stored in courses that are not intended for public access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the LearnPress plugin to a version patched against CVE-2026-93882 immediately.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block requests to the 'lp-ajax-handle' endpoint that contain suspicious 'item_id' parameters if a patch cannot be immediately deployed.\u003c/li\u003e\n\u003cli\u003eReview access logs for high-frequency requests to the 'lp-ajax-handle' endpoint from unauthenticated users, specifically looking for variations in the 'item_id' field.\u003c/li\u003e\n\u003cli\u003eAudit current LearnPress configurations to ensure that sensitive materials are not stored in courses with 'No Required Enroll' enabled until the update is applied.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T08:39:53Z","date_published":"2026-10-01T08:39:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-learnpress-idor/","summary":"An unauthenticated IDOR vulnerability in the LearnPress WordPress plugin allows unauthorized access to private course materials by manipulating the course and item identifiers in AJAX requests.","title":"CVE-2026-93882 - IDOR in LearnPress WordPress LMS Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-learnpress-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}