Medium severity5.3NVD Advisory· Published Jan 6, 2026· Updated Jun 17, 2026
CVE-2025-13964
CVE-2025-13964
Description
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents by adding/removing/updating/re-ordering sections or modifying section items.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=4.3.2+ 1 more
- (no CPE)range: <=4.3.2
- (no CPE)range: <=4.3.2
- Range: <=4.3.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.