SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78125

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The LearnPress WordPress plugin versions prior to 4.0.3 are vulnerable due to a lack of authorization checks on a REST endpoint, enabling unauthenticated attackers to disclose the payment status of any order by simply guessing order identifiers. This vulnerability poses a risk of sensitive information leakage, which could be exploited for further attacks or fraud. WordPress site administrators using the LearnPress plugin should prioritize updating to version 4.0.3 or later to mitigate this risk.

CVE
CVE-2026-78125
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.