S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Feb 11, 2026

CVE-2025-13956 Scanner

CVE-2025-13956 Scanner - Information Disclosure vulnerability in LearnPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-13956
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total revenue summaries and order status counts

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesby thimpress
0
Updated Aug 19, 2026View on NVD →
Detail

LearnPress is a popular Learning Management System (LMS) plugin for WordPress, designed to facilitate the creation and management of online courses and educational content. Developed by ThimPress, it is used by educational institutions, online course providers, and individual educators. The plugin allows users to create lessons, quizzes, and assignments with ease. The intuitive interface and integration with WordPress make it an accessible option for those looking to launch online learning platforms. Additionally, its wealth of features supports user engagement and course monetization. LearnPress is extensible with add-ons, allowing for a customized learning environment.

The Information Disclosure vulnerability in LearnPress arises due to a lack of proper capability checks on certain functions. This flaw allows unauthenticated attackers to access sensitive data within the plugin. Specifically, they can view order statistics such as total revenue summaries and order status counts. The vulnerability affects LearnPress versions up to and including 4.3.1. By exploiting this security flaw, attackers gain unauthorized insight into financial and transactional metrics. This issue underscores the importance of maintaining robust access controls to protect sensitive information.

Technically, this vulnerability manifests due to the missing capability check on the statistics function within LearnPress. The vulnerable endpoint, reachable via a GET request at '/wp-json/lp/v1/orders/statistic', lacks proper authorization mechanisms. The response includes sensitive information like "total-raised" and "order-completed" if the attacker can satisfy specific conditions related to the response body and status code. The flaw highlights a critical gap in access control, allowing unauthorized users to retrieve confidential data. Ensuring proper verification and limiting access to authenticated users is essential for preventing such issues.

Potential consequences of exploiting this vulnerability include unauthorized access to sensitive financial data. An attacker could use the disclosed information to gain insights into business operations, potentially leading to competitive disadvantages. The exposure of revenue data and order status could also lead to financial losses if exploited for nefarious purposes. Furthermore, this breach of information can undermine customer trust, damaging the brand's reputation. It stresses the need for immediate remediation and continuous security assessments to prevent unauthorized data exposure.

REFERENCES

Solution Advice
  • Update LearnPress to a version later than 4.3.1 to patch the vulnerability.
  • Implement proper capability checks on all sensitive endpoints.
  • Regularly review and audit access controls and permissions.
  • Educate your development team on secure coding practices to prevent future vulnerabilities.
  • Conduct regular security assessments to identify and address other potential security gaps.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.