Description
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
Published: 2026-09-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken object‑level authorization flaw that permits any authenticated user with the Instructor role to add answers to quiz questions that belong to other instructors. By supplying arbitrary question identifiers on the answer insertion endpoint, the attacker can bypass the ownership check and persistently alter quiz content that they should not be allowed to modify, creating a medium‑severity data integrity issue.

Affected Systems

This flaw exists in the LearnPress WordPress Plugin from ThimPress for all versions prior to 4.4.6. The vulnerability is only exploitable by users with the Instructor role who can access the plugin’s quiz functionality.

Risk and Exploitability

With a CVSS score of 5.3 the risk is medium, and the EPSS score is not available so the probability of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. It is likely to be exploited by an authenticated attacker with instructor privileges who can manipulate quiz data by submitting arbitrary question IDs to the answer insertion path.

Generated by OpenCVE AI on September 3, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LearnPress to version 4.4.6 or later, which contains the missing ownership check.
  • If an upgrade is not possible, reduce the Instructor role’s capabilities so that instructors cannot add quiz answers to questions that do not belong to them.
  • Add custom code or a hook that verifies question ownership before processing quiz answer insertions, ensuring the instructor’s ID matches the question’s owner.

Generated by OpenCVE AI on September 3, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Thimpress
Thimpress learnpress
Wordpress
Wordpress wordpress
Vendors & Products Thimpress
Thimpress learnpress
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
Title LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Thimpress Learnpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T18:00:03.440Z

Reserved: 2026-08-27T21:39:20.459Z

Link: CVE-2026-82023

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T18:17:24.260

Modified: 2026-09-03T18:17:24.260

Link: CVE-2026-82023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:15:06Z

Weaknesses