CVE-2025-14798: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14798 is a sensitive information exposure vulnerability in the LearnPress – WordPress LMS Plugin affecting versions up to and including 4.3.2.4. The flaw exists in the get_item_permissions_check function, which fails to properly restrict access to user data, allowing unauthenticated attackers to extract user first names, last names, social profile links, and course enrollment details. It was published on January 20, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the get_item_permissions_check function in the LearnPress REST API controller (class-lp-rest-users-v1-controller.php) does not enforce authentication or capability checks before returning user profile data. An unauthenticated attacker can send HTTP GET requests to the exposed REST API endpoint and receive sensitive user information in the response. No special privileges, user interaction, or complex conditions are required for exploitation (Wordfence, LearnPress Source).

Impact

Successful exploitation results in unauthorized disclosure of user personal information including first and last names, social profile links, and course enrollment data from WordPress sites running the affected plugin. While integrity and availability are not impacted, the exposed data could facilitate targeted phishing, social engineering, or account enumeration attacks against platform users. The network-accessible nature of the vulnerability means attackers can harvest data at scale from any internet-facing LearnPress installation (Wordfence).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-14798. The EPSS score is approximately 0.037%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the zero-authentication requirement and network accessibility make it trivially exploitable if targeted (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the LearnPress plugin (version ≤ 4.3.2.4) using tools like WPScan, Shodan, or by checking /wp-content/plugins/learnpress/ for version indicators.
  2. Locate the vulnerable REST API endpoint: The affected endpoint is exposed via the LearnPress JWT REST API, typically accessible at /wp-json/lp/v1/users/<user_id> or a similar path handled by class-lp-rest-users-v1-controller.php.
  3. Send unauthenticated request: Issue an HTTP GET request to the endpoint without any authentication headers or tokens, e.g., curl -s https://target.com/wp-json/lp/v1/users/1.
  4. Harvest user data: Parse the JSON response to extract user first names, last names, social profile links, and enrollment information. Iterate over sequential user IDs to enumerate multiple users at scale (Wordfence, LearnPress Source).

Indicators of compromise

  • Network: Repeated unauthenticated HTTP GET requests to /wp-json/lp/v1/users/ endpoints with sequential or enumerated user IDs from a single or rotating IP address.
  • Logs: WordPress access logs showing high-frequency requests to LearnPress REST API paths (e.g., /wp-json/lp/v1/users/*) without authentication headers, particularly from automated tools (unusual User-Agent strings or high request rates).
  • Logs: HTTP 200 responses to unauthenticated REST API requests that should require authentication, indicating the vulnerable code path was triggered.

Mitigation and workarounds

Users should update the LearnPress – WordPress LMS Plugin to a version beyond 4.3.2.4 that includes a fix for the missing authorization check in get_item_permissions_check. As an interim measure, site administrators can restrict access to the WordPress REST API for unauthenticated users using security plugins (e.g., Wordfence, Disable REST API) or web application firewall rules blocking unauthenticated requests to /wp-json/lp/v1/users/. Monitoring access logs for unusual REST API activity is also recommended (Wordfence, Sucuri Blog).

Community reactions

Sucuri included CVE-2025-14798 in their January 2026 vulnerability patch roundup, highlighting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). Wordfence published a threat intelligence entry cataloging the vulnerability details and affected versions (Wordfence). Social media activity was minimal, with brief automated posts on Bluesky noting the CVE disclosure.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management