Impact
LearnPress, a widely used WordPress plugin, has a disclosure flaw in versions 4.4.3 through 4.4.6. The plugin’s REST endpoint for checking quiz answers fails to enforce authentication or role checks, returning the correctness flag, the actual correct answer, and the instructor’s explanation to any request. This allows an unauthenticated visitor to obtain every answer option for each quiz question on courses that are marked as open to anyone, effectively leaking the course content.
Affected Systems
Affects the LearnPress WordPress plugin when installed in version 4.4.3, 4.4.4, 4.4.5, or 4.4.6 on sites that allow public or unenrolled participation in courses. The issue was addressed in the 4.4.7 release.
Risk and Exploitability
The CVSS score of 3.7 indicates low impact severity, and the EPSS score of less than 1% with absence in the KEV catalog suggests the current likelihood of exploitation is low. However, because the flaw is unauthenticated and exposed through WordPress’s REST API, any user can invoke the check-answer route and obtain protected content. The vulnerability represents a data disclosure risk that can undermine course integrity, even though large‑scale attacks are currently unlikely.
OpenCVE Enrichment