PT-2026-21374 · WordPress+1 · Learnpress Export Import+2

Os

+1

·

Published

2026-02-21

·

Updated

2026-02-22

·

CVE-2026-1787

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions LearnPress Export Import versions up to and including 4.1.0
Description The LearnPress Export Import WordPress extension for the LearnPress plugin is affected by a flaw that allows unauthorized data loss. A missing capability check within the delete migrated data() function permits unauthenticated attackers to delete courses migrated from Tutor LMS. The Tutor LMS plugin must be installed and activated for exploitation to occur.
Recommendations Versions prior to 4.1.1 should be updated.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1787

Affected Products

Learnpress
Learnpress Export Import
Tutor Lms