Description
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress WordPress plugin before 4.4.7 otherwise keeps non-public.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized information disclosure
Action: Upgrade
AI Analysis

Impact

An administrative template handler in the LearnPress WordPress plugin fails to verify the calling user’s capabilities, allowing an attacker to retrieve the text, identifier and type of every published quiz question, as well as perform keyword searches over the entire question bank. Because this data is normally kept non‑public, an unauthenticated user can obtain sensitive educational material without permission, exposing potential intellectual property and user data. The weakness aligns with CWE‑200 Information Exposure, indicating that adequate access control is missing.

Affected Systems

Any WordPress site that has installed LearnPress version 4.4.6 or earlier is affected. The plugin versions that lack the capability checks include all releases prior to 4.4.7; site administrators should verify their installed plugin version to determine exposure.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The EPSS score of less than 1% suggests a very low exploitation probability at the time of this analysis, and the vulnerability is not listed in CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the load_content_via_ajax AJAX endpoint, which is exposed over the public web. Based on the description, it is inferred that the endpoint does not enforce any permission checks, allowing attackers to enumerate and retrieve the entire quiz bank without authentication.

Generated by OpenCVE AI on September 20, 2026 at 05:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the LearnPress plugin to version 4.4.7 or later.
  • If an upgrade cannot be performed immediately, modify the load_content_via_ajax AJAX handler to reject requests from unauthenticated users by adding a capability check or disabling the endpoint for non‑logged‑in visitors.
  • Implement monitoring of web logs to detect anomalous access patterns to the AJAX handler and notify administrators of suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 05:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Learnpress
Learnpress learnpress
Wordpress
Wordpress wordpress
Vendors & Products Learnpress
Learnpress learnpress
Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress WordPress plugin before 4.4.7 otherwise keeps non-public.
Title LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax
References

Subscriptions

Learnpress Learnpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:34:56.716Z

Reserved: 2026-09-07T12:51:45.155Z

Link: CVE-2026-86445

cve-icon Vulnrichment

Updated: 2026-09-17T12:17:12.098Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:34.583

Modified: 2026-09-17T13:16:51.773

Link: CVE-2026-86445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor