PT-2026-24912 · Thimpress · Learnpress – Wordpress Lms Plugin For Create/Sell Online Courses
Jack Pas
·
Publicado
2026-03-12
·
Atualizado
2026-03-12
·
CVE-2026-3226
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LearnPress – WordPress LMS Plugin versions up to and including 4.3.2.8
Description
The LearnPress – WordPress LMS Plugin is susceptible to unauthorized email notification triggering. This occurs because of missing capability checks in all 10 functions within the
SendEmailAjax class. The AbstractAjax::catch lp ajax() dispatcher verifies a wp rest nonce but does not perform a current user can() check before dispatching to handler functions. The wp rest nonce is embedded in the frontend JavaScript for all authenticated users. This allows authenticated attackers with Subscriber-level access or higher to trigger arbitrary email notifications to administrators, instructors, and users. This can lead to email flooding, social engineering, and impersonation of administrative decisions regarding instructor requests.Recommendations
Versions up to and including 4.3.2.8 should be updated to a newer, fixed version when available.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Learnpress – Wordpress Lms Plugin For Create/Sell Online Courses