The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request
References
Configurations
No configuration.
History
17 Jun 2026, 14:50
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-17 13:21
Updated : 2026-06-17 14:50
NVD link : CVE-2026-8383
Mitre link : CVE-2026-8383
CVE.ORG link : CVE-2026-8383
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
