CVE-2025-14802

LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a parameter mismatch between the DELETE operation and authorization check, where the endpoint uses file_id from the URL path but the permission callback validates item_id from the request body. This makes it possible for authenticated attackers, with teacher-level access, to delete arbitrary lesson material files uploaded by other teachers via sending a DELETE request with their own item_id (to pass authorization) while targeting another teacher's file_id.


We have discovered 9,060 live websites that are affected by CVE-2025-14802.

Run a Free Instant Scan




Affected Software

Product  LearnPress
Category Learning Management System
Vulnerable Domains9,060 live websites (92% of LearnPress install base)
Vulnerable Versions
  • from 0 through 4.3.2.1
Vulnerable Versions Count150 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jan 7, 2026
  • Updated - Jan 7, 2026

Credits

  • Deniz Mert (finder)

Website Distribution by Country

Number of websites using CVE-2025-14802
United States2,490 websites



Germany631 websites
India497 websites
France384 websites
Spain381 websites
Italy355 websites
GB343 websites
Cyprus320 websites
Brazil248 websites
Poland229 websites

Website Distribution by TLD

Number of websites using CVE-2025-14802
.com3,910 websites
.org679 websites
.it237 websites
.com.br206 websites
.de203 websites
.net202 websites
.pl158 websites
.es157 websites
.fr139 websites
.ru133 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14802

Top websites that are affected by CVE-2025-14802. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.center Germany**,***
******.***.uk GB***,***
**************************.org United States***,***
**************.com United States***,***
************.org United States***,***
********************.fr France***,***
***********.*********.com United States***,***
*******.****.br Brazil***,***
********.***.my United States***,***
******************.com United States***,***
See full domain list

FAQ

CVE-2025-14802 is Authorization Bypass Through User-Controlled Key in LearnPress
A total of 9,060 websites have been identified as vulnerable to CVE-2025-14802, based on global website indexing conducted by WebTechSurvey.
The LearnPress is affected by the CVE-2025-14802 vulnerability.
LearnPress versions up to and including 4.3.2.1 are vulnerable to CVE-2025-14802.