LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by insecure handling in class-lp-rest-material-controller.php, letting unauthenticated attackers extract paid course material, exploit requires no authentication.
id: CVE-2024-11868
info:
name: LearnPress < 4.2.7.4 - Course Material - Information Disclosure
...