CVE-2025-66054Missing Authorization in Learnpress

Severity
7.5HIGHNVD
EPSS
0.0%
top 87.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18

Description

Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.9.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

CVEListV5thimpress/learnpress4.2.9.4

🔴Vulnerability Details

2
CVEList
WordPress LearnPress plugin <= 4.2.9.4 - Broken Access Control vulnerability2025-12-18
GHSA
GHSA-jwqw-35vc-8x2r: Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels2025-12-18

🕵️Threat Intelligence

1
Wiz
CVE-2025-66054 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-66054 — Missing Authorization in Learnpress | cvebase