Loading market data...
← Back to CVE feed

CVE-2026-86449

UNKNOWN View on NVD ↗

Description

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.

Published: Sep 16, 2026 06:16 UTC Modified: Sep 16, 2026 20:25 UTC