CVE-2026-86449
Last modified
CVE-2026-86449 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that are not published, including draft, pending, private, scheduled and trashed ones.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | LearnPress | >= 4.2.7.1, < 4.4.7 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86449?
How severe is CVE-2026-86449?
How do I fix CVE-2026-86449?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86443Cleartext storage of sensitive information in the DuoxMe app…6.9
- CVE-2026-86444The LearnPress WordPress plugin before 4.4.7 does not escap…7.1
- CVE-2026-86445The LearnPress WordPress plugin before 4.4.7 does not check…5.3
- CVE-2026-86446The LearnPress WordPress plugin before 4.4.7 does not restr…3.7
- CVE-2026-86447The LearnPress WordPress plugin before 4.4.7 does not check…5.3
- CVE-2026-86448The LearnPress WordPress plugin before 4.4.7 does not perfo…3.7
- CVE-2026-86451Affected versions of MISP allow authenticated users to retri…4.3
- CVE-2026-86452Affected versions of MISP permit unauthenticated or weakly c…7.5
- CVE-2026-8646IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphe…9.1
- CVE-2026-86460Cypher injection vulnerability in the Neo4j persistence laye…9.8
- CVE-2026-86462Apache Airflow FAB provider: changing a user's password thro…9.1
- CVE-2026-86464In the current development version of Eclipse aeriOS, for wh…9.9
Are you affected by CVE-2026-86449?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
