<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LearnPress (&lt;= 4.4.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/learnpress--4.4.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 08:39:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/learnpress--4.4.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-93882 - IDOR in LearnPress WordPress LMS Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-learnpress-idor/</link><pubDate>Thu, 01 Oct 2026 08:39:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-learnpress-idor/</guid><description>An unauthenticated IDOR vulnerability in the LearnPress WordPress plugin allows unauthorized access to private course materials by manipulating the course and item identifiers in AJAX requests.</description><content:encoded><![CDATA[<p>CVE-2026-93882 describes an Insecure Direct Object Reference (IDOR) vulnerability within the LearnPress WordPress plugin, impacting versions up to and including 4.4.8. The vulnerability resides in the CourseMaterialTemplate::render_material_items() callback, which is exposed through the public 'lp-ajax-handle' endpoint. This specific endpoint is included in the plugin's no-nonce allowlist and lacks necessary capability checks.</p>
<p>The flaw occurs because the handler performs authorization validation based solely on an attacker-supplied 'course_id', while retrieving course-material records using an independently attacker-supplied 'item_id'. By targeting a site that has at least one course with 'No Required Enroll' enabled, an unauthenticated attacker can supply the identifier of a public course to bypass initial checks and then leverage the 'item_id' parameter to retrieve, read, or download materials associated with private, paid, or enrollment-restricted courses. This exposure poses a significant risk to the confidentiality of proprietary educational content and student-accessible materials.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a WordPress site running LearnPress version 4.4.8 or earlier.</li>
<li>Attacker discovers the public 'lp-ajax-handle' endpoint exposed by the plugin.</li>
<li>Attacker identifies at least one course on the target site with the 'No Required Enroll' setting enabled.</li>
<li>Attacker crafts an AJAX request to the endpoint, setting the 'action' parameter to 'load_content_via_ajax'.</li>
<li>Attacker provides the 'course_id' of the public course to pass the superficial authorization check within the handler.</li>
<li>Attacker provides the 'item_id' corresponding to a private or paid resource in the target course.</li>
<li>The vulnerable 'render_material_items()' method processes the request, ignoring the ownership check between the 'course_id' and 'item_id'.</li>
<li>The server returns the sensitive file path or external URL for the requested private material to the attacker.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated users to gain unauthorized access to private and paid course materials. This results in the potential leak of proprietary intellectual property, protected digital assets, and sensitive student resources. The vulnerability affects any site utilizing LearnPress for LMS functionality where sensitive materials are stored in courses that are not intended for public access.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the LearnPress plugin to a version patched against CVE-2026-93882 immediately.</li>
<li>Implement a Web Application Firewall (WAF) rule to inspect and block requests to the 'lp-ajax-handle' endpoint that contain suspicious 'item_id' parameters if a patch cannot be immediately deployed.</li>
<li>Review access logs for high-frequency requests to the 'lp-ajax-handle' endpoint from unauthenticated users, specifically looking for variations in the 'item_id' field.</li>
<li>Audit current LearnPress configurations to ensure that sensitive materials are not stored in courses with 'No Required Enroll' enabled until the update is applied.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>idor</category><category>wordpress</category><category>lms</category><category>web-application-vulnerability</category></item></channel></rss>