S4E just found a high [ai] pa ssl inspection control
medium·Product Based Web Vulnerabilities·Updated Feb 8, 2026

CVE-2024-5483 Scanner

CVE-2024-5483 Scanner - Information Disclosure vulnerability in LearnPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5483
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic information about website users, including their emails

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesby thimpress
0
Updated Aug 19, 2026View on NVD →
Detail

LearnPress is a popular WordPress LMS plugin used globally by educators, institutions, and e-learning platforms to manage online learning environments. This plugin allows users to create courses, manage learners, and track progress effectively and efficiently within WordPress. Many educational websites and school portals rely on LearnPress to deliver a seamless educational experience. It provides robust capabilities for managing course content, quizzes, and learner interactions, making it a preferred choice for creating dynamic educational content.

The Information Disclosure vulnerability in LearnPress allows unauthenticated attackers to access sensitive user data. This vulnerability results from an incorrect implementation of the get_items_permissions_check function in versions up to 4.2.6.8. When exploited, attackers can extract user details such as emails and usernames without authorization. This exposure can lead to significant privacy and security issues if left unaddressed.

Technical details of the vulnerability involve access to the endpoint {{BaseURL}}/wp-json/learnpress/v1/users, which returns a JSON response with user data. The vulnerability stems from improper permission checks, allowing anyone to retrieve this sensitive information without needing any authentication. The information disclosed includes user emails and usernames, which can be viewed when the server returns status code 200 and content type "application/json". The regular expression is used to extract these details from the JSON response payload.

When exploited, this vulnerability can lead to unauthorized access to critical user information, including email addresses, potentially opening avenues for phishing attacks, spam campaigns, and other privacy breaches. Users' personal data could be compromised, leading to trust issues and reputational damage to the websites using the vulnerable plugin. Information exposure could be leveraged for social engineering attacks targeting affected users.

REFERENCES

Solution Advice
  • Update the LearnPress plugin to version 4.2.6.9 or later to mitigate the vulnerability.
  • Regularly audit plugins for vulnerabilities and apply security patches promptly.
  • Implement web application firewalls (WAF) to block unauthorized access attempts to sensitive endpoints.
  • Restrict access to sensitive information by implementing robust authentication and permission checks.
  • Conduct regular security assessments to identify potential vulnerabilities in web applications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-5483 Scanner - Information Disclosure vulnerability in LearnPress S4E