Sceawere
Vulnerability Detail
CVE-2026-104403UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LearnPress Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 13h ago
- Vendor
- ThimPress
- Product
- LearnPress
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T10:17:06.947Z",
"pubdate": "2026-10-02T10:17:06.947Z",
"executiveSummary": "This vulnerability, classified as an Authorization Bypass Through User-Controlled Key, affects ThimPress LearnPress versions from n/a through 4.4.9.\nThe flaw resides in an incorrectly configured access control mechanism, allowing unauthorized entities to manipulate security levels or bypass authorization checks by modifying user-controlled keys.\nThe vulnerability poses a significant risk to the integrity and confidentiality of the LearnPress LMS environment. By successfully exploiting this flaw, an attacker could potentially gain unauthorized access to administrative functions, restricted content, or sensitive user data without possessing the requisite permissions.\nThe impact is categorized as high, as it compromises the core security posture of the application. Exploitation does not necessarily require high-level credentials, depending on the specific implementation of the key validation logic, potentially allowing unauthenticated or low-privileged users to escalate privileges.\nOrganizations utilizing affected versions of LearnPress are exposed to unauthorized configuration changes and potential system-wide compromise. There are no specific external network requirements mentioned, as the vulnerability is inherent to the application's request handling and validation logic.",
"technicalDetails": "The vulnerability stems from improper validation and trust in client-supplied input used to determine authorization status within LearnPress. Specifically, the application relies on a user-controlled key to govern access to restricted resources or administrative operations. By failing to server-side validate the integrity and authenticity of this key against a secure session or server-side store, the system allows the key to be bypassed or manipulated.\nThe root cause is an insecure access control implementation where the security state is derived from mutable user-provided data. This effectively delegates authorization decisions to the client, which is a fundamental security anti-pattern. An attacker can manipulate the request parameters or headers containing this key to trick the application into elevating the requester's privileges or granting access to protected endpoints.\nThe attack flow typically follows this trajectory: First, an attacker identifies a target endpoint or function that uses the vulnerable key mechanism to enforce access control. Second, the attacker intercept the HTTP request and identifies the specific parameter acting as the 'user-controlled key'. Third, the attacker modifies this key, potentially by providing a crafted payload, a null value, or a known 'master' or 'admin' key value if the logic is poorly implemented. Fourth, the application processes the request, incorrectly validates the user-supplied key as legitimate, and grants the requested unauthorized action or access.\nThis behavior exposes the application to severe post-exploitation consequences, including unauthorized course management, user account modification, and sensitive data extraction. Because the authorization check is bypassed at the source, any function protected solely by this mechanism is rendered vulnerable. The exposure is internal to the WordPress environment but accessible via standard HTTP requests, meaning any attacker capable of reaching the web server can attempt exploitation. Given that the versions affected range from n/a to 4.4.9, the vulnerability represents a long-standing weakness in the plugin's access control architecture, requiring a comprehensive audit of all functions utilizing similar parameter-based authorization checks."
}