Wordpress Alert: LMS course access bypass

A course route exposes lessons to a user who has not enrolled. Paid or restricted learning material may leak.

What it looks like

A course route exposes lessons to a user who has not enrolled.

Why it matters

Paid or restricted learning material may leak.

What to check

Test lessons and files as signed-out and unenrolled users.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress REST endpoint permissions.