All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-12976
MEDIUMpublished 2026-08-12 06:17 UTC · 21 hours ago · modified 2026-08-12 20:17 UTC
6.5
CVSS / 10
// description
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a subscriber to obtain material from paid courses they have not enrolled in.
// weaknesses (CWE)
- CWE-200