CVE-2025-11368 Details
Description
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.
A vulnerability allowing sensitive information disclosure exists in the LearnPress WordPress LMS Plugin, affecting all versions through 4.2.9.4. The issue arises from inadequate capability checks in the REST endpoint '/wp-json/lp/v1/load_content_via_ajax', which permits unauthenticated users to execute arbitrary callbacks of admin-only template methods. This flaw enables the retrieval of confidential educational content, such as admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive data, via the REST API, provided valid numeric IDs are supplied.
Users are advised to update the LearnPress WordPress LMS Plugin to version 4.3.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 21, 2025CISA-ADP
Assessed Nov 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ThimPress LearnPress | <= 4.2.9.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2025 | New CVE Received | [email protected] |
Volerion