216.73.216.197

CVE-2025-14802

· Published 07/01/2026 12:16 · Modified 08/01/2026 18:08

Labels: CVE-2025-14802 2026-01-07CVE-2025-14802CWE-639[email protected]

Essential information

Published
07/01/2026 12:16
Modified
08/01/2026 18:08
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CVSS metrics

Description

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a parameter mismatch between the DELETE operation and authorization check, where the endpoint uses file_id from the URL path but the permission callback validates item_id from the request body. This makes it possible for authenticated attackers, with teacher-level access, to delete arbitrary lesson material files uploaded by other teachers via sending a DELETE request with their own item_id (to pass authorization) while targeting another teacher's file_id.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
learnpress / learnpress cpe:2.3:a:learnpress:learnpress:<4.3.2.2:*:*:*:*:wordpress:*:*

References