CVE-2026-75982

LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter

The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX action. The LP_Admin_Ajax::create_page() handler only checks the edit_pages capability and a wp_rest nonce (both available to Editors), then reads the field_name parameter from the request without restricting it to a learn_press_* allow-list before passing it as the option key to LP_Helper::create_page(), which calls update_option($key_option, $page_id). This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrary WordPress options to a positive integer (a newly created page ID), enabling actions such as flipping users_can_register to a truthy value to open public registration, corrupting active_plugins to break the site, or otherwise tampering with site-wide settings normally reserved for administrators.


We have discovered 9,687 live websites that are affected by CVE-2026-75982.

Run a Free Instant Scan




Affected Software

Product  LearnPress
Category Learning Management System
Vulnerable Domains9,687 live websites (100% of LearnPress install base)
Vulnerable Versions
  • from 0 through 4.4.4
Vulnerable Versions Count169 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 25, 2026
  • Updated - Aug 25, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-75982
United States2,742 websites



Germany645 websites
India542 websites
Spain418 websites
France387 websites
GB384 websites
Italy373 websites
Cyprus308 websites
Poland264 websites
Brazil253 websites

Website Distribution by TLD

Number of websites using CVE-2026-75982
.com4,222 websites
.org773 websites
.it246 websites
.net216 websites
.de210 websites
.com.br206 websites
.pl184 websites
.es159 websites
.co.uk144 websites
.fr137 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75982

Top websites that are affected by CVE-2026-75982. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.app United States**,***
******.center Germany**,***
***.org United States**,***
**********.com United States**,***
******.***.uk GB***,***
*******.org United States***,***
**************************.org United States***,***
************.org United States***,***
********************.fr France***,***
*********.***********.com United States***,***
See full domain list

FAQ

CVE-2026-75982 is Missing Authorization in LearnPress
A total of 9,687 websites have been identified as vulnerable to CVE-2026-75982, based on global website indexing conducted by WebTechSurvey.
The LearnPress is affected by the CVE-2026-75982 vulnerability.
LearnPress versions up to and including 4.4.4 are vulnerable to CVE-2026-75982.