PT-2026-24912 · Thimpress · Learnpress – Wordpress Lms Plugin For Create/Sell Online Courses

Jack Pas

·

Published

2026-03-12

·

Updated

2026-03-12

·

CVE-2026-3226

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions LearnPress – WordPress LMS Plugin versions up to and including 4.3.2.8
Description The LearnPress – WordPress LMS Plugin is susceptible to unauthorized email notification triggering. This occurs because of missing capability checks in all 10 functions within the SendEmailAjax class. The AbstractAjax::catch lp ajax() dispatcher verifies a wp rest nonce but does not perform a current user can() check before dispatching to handler functions. The wp rest nonce is embedded in the frontend JavaScript for all authenticated users. This allows authenticated attackers with Subscriber-level access or higher to trigger arbitrary email notifications to administrators, instructors, and users. This can lead to email flooding, social engineering, and impersonation of administrative decisions regarding instructor requests.
Recommendations Versions up to and including 4.3.2.8 should be updated to a newer, fixed version when available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3226

Affected Products

Learnpress – Wordpress Lms Plugin For Create/Sell Online Courses