CVE-2025-14802: Thimpress Learnpress – WordPress Lms Plugin For Create And Sell Online Courses
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a parameter mismatch between the DELETE operation and authorization check, where the endpoint uses file_id from the URL path but the permission callback validates item_id from the request body. This makes it possible for authenticated attackers, with teacher-level access, to delete arbitrary lesson material files uploaded by other teachers via sending a DELETE request with their own item_id (to pass authorization) while targeting another teacher's file_id.
Affected products
- Thimpress Learnpress – WordPress Lms Plugin For Create And Sell Online Courses: up to and including 4.3.2.1
Published 2026-01-07. Last modified 2026-10-07.