Description

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course material.

INFO

Published Date :

2024-12-10T12:24:59.516Z

Last Modified :

2026-04-08T17:02:33.522Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-11868 vulnerability.

Vendors Products
Thimpress
  • Learnpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact