CVE-2026-1787

MEDIUM

LearnPress Export Import 4.1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to delete course that have been migrated from Tutor LMS. The Tutor LMS plugin must be installed and activated in order to exploit the vulnerability.

Scores

CVSS v3 4.8
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
thimpress/LearnPress – Backup & Migration Tool < 4.1.0
Published Feb 21, 2026
Tracked Since Feb 21, 2026