Record summary

CVE-2025-13956 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total revenue summaries and order status counts

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Browse thimpress / LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Default status: unaffected

CVE ListThrough 4.3.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLearnPress < 4.3.2 - Broken Access ControlCVSS 5.3

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total revenue summaries and order status counts.

Impact

Unauthenticated attackers can view sensitive order statistics including revenue and order status, leading to information disclosure.

Remediation

Update to a version later than 4.3.1 or the latest available version.

WeaknessesCWE-862
Authorspussycat0x
Template tagscvecve2025wordpresswp-pluginwplearnpressexposure
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: http.html:"/wp-content/plugins/learnpress/"
FOFA: body="/wp-content/plugins/learnpress/"

Source: ProjectDiscovery

References

3