The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX action. The LP_Admin_Ajax::create_page() handler only checks the edit_pages capability and a wp_rest nonce (both available to Editors), then reads the field_name parameter from the request without restricting it to a learn_press_* allow-list before passing it as the option key to LP_Helper::create_page(), which calls update_option($key_option, $page_id). This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrary WordPress options to a positive integer (a newly created page ID), enabling actions such as flipping users_can_register to a truthy value to open public registration, corrupting active_plugins to break the site, or otherwise tampering with site-wide settings normally reserved for administrators.
We have discovered 9,687 live websites that are affected by CVE-2026-75982.
| Product | |
| Category | Learning Management System |
| Vulnerable Domains | 9,687 live websites (100% of LearnPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 169 versions ( 98% of all versions) |
| 2,742 websites | |
| 645 websites | |
| 542 websites | |
| 418 websites | |
| 387 websites | |
| 384 websites | |
| 373 websites | |
| 308 websites | |
| 264 websites | |
| 253 websites |
| .com | 4,222 websites |
| .org | 773 websites |
| .it | 246 websites |
| .net | 216 websites |
| .de | 210 websites |
| .com.br | 206 websites |
| .pl | 184 websites |
| .es | 159 websites |
| .co.uk | 144 websites |
| .fr | 137 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.app | **,*** | ||
| ******.center | **,*** | ||
| ***.org | **,*** | ||
| **********.com | **,*** | ||
| ******.***.uk | ***,*** | ||
| *******.org | ***,*** | ||
| **************************.org | ***,*** | ||
| ************.org | ***,*** | ||
| ********************.fr | ***,*** | ||
| *********.***********.com | ***,*** |
FAQ