Undefined · Undefined · CVE-2026-8383
**Name of the Vulnerable Software and Affected Versions**
LearnPress versions prior to 4.3.7
**Description**
An information disclosure issue exists where the `edit` context on a REST endpoint is not properly restricted by the `edit users` capability. This allows unauthenticated visitors to retrieve sensitive user data, including roles, full capabilities map, extra capabilities, locale, and registration date, by sending a crafted request.
**Recommendations**
Update LearnPress to version 4.3.7 or later.