S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 8, 2026

CVE-2025-11368 Scanner

CVE-2025-11368 Scanner - Arbitrary Callback Execution to Information Exposure vulnerability in LearnPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-11368
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesby thimpress
0
Updated Aug 22, 2026View on NVD →
Detail

The LearnPress WordPress LMS Plugin is widely used in educational institutions and online learning platforms. Developed by ThimPress, it facilitates the creation of courses, lessons, and quizzes on WordPress websites. This plugin enables educators to manage and sell online courses, quizzes, and related educational content. It integrates with various other WordPress plugins and themes to provide a comprehensive e-learning solution. LearnPress is popular due to its flexibility and the extensive range of features it offers for both instructors and learners. However, regular updates and security patches are essential to maintain its security.

The Arbitrary Callback Execution to Information Exposure vulnerability in LearnPress occurs due to insufficient capability checks in certain REST endpoints. This flaw allows unauthorized attackers to execute arbitrary admin-only template methods. It leads to the exposure of sensitive information such as admin curriculum HTML, quiz questions with correct answers, and course materials. The vulnerability compromises the confidentiality of educational content through the REST API endpoint. Attackers need to supply valid numeric IDs via the endpoint to exploit this vulnerability.

Technical details of the vulnerability involve missing capability checks in the REST endpoint `/wp-json/lp/v1/load_content_via_ajax`. Attackers can exploit this endpoint to execute arbitrary template methods intended for admin users. Successful exploitation enables attackers to access sensitive educational content by supplying valid numeric IDs in the API call. The vulnerable endpoint is publicly accessible, making it an attractive target for attackers. The template methods accessed through this vulnerability include those that render or fetch sensitive educational data.

Exploitation of this vulnerability can lead to unauthorized disclosure of sensitive educational content. This includes quiz answers, curriculum materials, and other proprietary educational content intended for admin or instructor access only. Such unauthorized access can undermine the integrity of the educational content and services provided by affected institutions or platforms. Moreover, it may result in reputational damage and financial loss if proprietary material is leaked or misused.

REFERENCES

Solution Advice
  • Update LearnPress to the latest version beyond 4.2.9.4 to mitigate this vulnerability.
  • Regularly review and apply security updates and patches provided by LearnPress developers.
  • Consider implementing additional security plugins or services to monitor and secure REST API endpoints.
  • Restrict access to sensitive endpoints and consider using role-based access controls to limit who can access specific functionalities.
  • Monitor access logs for any unusual or unauthorized access patterns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.