漏洞情报聚合

CVE-2026-78125 - The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers. - 漏洞详情

漏洞编号:CVE-2026-78125

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-78125

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-200

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment status of arbitrary orders by enumerating order identifiers.

相关链接

相关漏洞

« 返回首页