PT-2026-1581 · WordPress · Wordpress+1
Deniz Mert
·
Publicado
2026-01-07
·
Atualizado
2026-01-07
·
CVE-2025-14802
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
LearnPress – WordPress LMS Plugin for WordPress versions up to and including 4.3.2.2
Description
The LearnPress – WordPress LMS Plugin for WordPress is susceptible to unauthorized file deletion. This is caused by a discrepancy in parameter handling during the authorization check for the DELETE operation. The
/wp-json/lp/v1/material/{file id} API endpoint utilizes file id from the URL path, while the permission callback validates item id from the request body. This allows authenticated attackers with teacher-level access to delete lesson material files uploaded by other teachers by sending a DELETE request with their own item id to bypass authorization while targeting another teacher's file id.Recommendations
Versions prior to 4.3.2.2 should be updated.
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Learnpress
Wordpress