CVE-2026-25002

WordPress LearnPress – Sepay Payment plugin <= 4.0.0 - Broken Authentication vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress – Sepay Payment: from n/a through <= 4.0.0.


We have discovered 1,006 live websites that are affected by CVE-2026-25002.

Run a Free Instant Scan




Affected Software

Product  LearnPress
Category Learning Management System
Vulnerable Domains1,006 live websites (10% of LearnPress install base)
Vulnerable Versions
  • from 0 through 4
Vulnerable Versions Count49 versions ( 31% of all versions)



Details

  • Published - Mar 25, 2026
  • Updated - Apr 29, 2026

Credits

  • Arif Shaikh | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-25002
United States210 websites



Spain65 websites
Italy58 websites
Russia57 websites
Germany53 websites
India49 websites
France42 websites
Brazil35 websites
Poland32 websites
GB31 websites

Website Distribution by TLD

Number of websites using CVE-2026-25002
.com394 websites
.org51 websites
.ru42 websites
.it35 websites
.com.br29 websites
.es23 websites
.pl21 websites
.eu20 websites
.de18 websites
.net17 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25002

Top websites that are affected by CVE-2026-25002. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********************.fr France***,***
*******.com United States***,***
************.com France***,***
********.****.cz Czech Republic*,***,***
***************.it Italy*,***,***
***************.it Italy*,***,***
**********.********.ro Romania*,***,***
***************.com Belgium*,***,***
****.es United States*,***,***
***.***.ng Nigeria*,***,***
See full domain list

FAQ

A total of 1,006 websites have been identified as vulnerable to CVE-2026-25002, based on global website indexing conducted by WebTechSurvey.
The LearnPress is affected by the CVE-2026-25002 vulnerability.
LearnPress versions up to and including 4 are vulnerable to CVE-2026-25002.