Impact
The vulnerability is a broken object‑level authorization flaw that permits any authenticated user with the Instructor role to add answers to quiz questions that belong to other instructors. By supplying arbitrary question identifiers on the answer insertion endpoint, the attacker can bypass the ownership check and persistently alter quiz content that they should not be allowed to modify, creating a medium‑severity data integrity issue.
Affected Systems
This flaw exists in the LearnPress WordPress Plugin from ThimPress for all versions prior to 4.4.6. The vulnerability is only exploitable by users with the Instructor role who can access the plugin’s quiz functionality.
Risk and Exploitability
With a CVSS score of 5.3 the risk is medium, and the EPSS score is not available so the probability of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. It is likely to be exploited by an authenticated attacker with instructor privileges who can manipulate quiz data by submitting arbitrary question IDs to the answer insertion path.
OpenCVE Enrichment