CyberRota Analysis
AI-GeneratedThe LearnPress WordPress plugin versions prior to 4.0.3 are vulnerable due to a lack of authorization checks on a REST endpoint, enabling unauthenticated attackers to disclose the payment status of any order by simply guessing order identifiers. This vulnerability poses a risk of sensitive information leakage, which could be exploited for further attacks or fraud. WordPress site administrators using the LearnPress plugin should prioritize updating to version 4.0.3 or later to mitigate this risk.
Original NVD Description
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.