The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-27 06:17
Updated : 2026-08-28 18:43
NVD link : CVE-2026-78125
Mitre link : CVE-2026-78125
CVE.ORG link : CVE-2026-78125
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
