Impact
An administrative template handler in the LearnPress WordPress plugin fails to verify the calling user’s capabilities, allowing an attacker to retrieve the text, identifier and type of every published quiz question, as well as perform keyword searches over the entire question bank. Because this data is normally kept non‑public, an unauthenticated user can obtain sensitive educational material without permission, exposing potential intellectual property and user data. The weakness aligns with CWE‑200 Information Exposure, indicating that adequate access control is missing.
Affected Systems
Any WordPress site that has installed LearnPress version 4.4.6 or earlier is affected. The plugin versions that lack the capability checks include all releases prior to 4.4.7; site administrators should verify their installed plugin version to determine exposure.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of less than 1% suggests a very low exploitation probability at the time of this analysis, and the vulnerability is not listed in CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the load_content_via_ajax AJAX endpoint, which is exposed over the public web. Based on the description, it is inferred that the endpoint does not enforce any permission checks, allowing attackers to enumerate and retrieve the entire quiz bank without authentication.
OpenCVE Enrichment