PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jun 28, 2026

LearnPress < 4.3.7 - Information Disclosure

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-8383
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnPress
AFFECTED< 4.3.7SAFE ✓≥ 4.3.7
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

LearnPress < 4.3.7 - Information Disclosure CVE-2026-8383 Scanner | S4E