CVE-2026-82023
Received Received - Intake

Broken Object-Level Authorization in LearnPress WordPress Plugin

Vulnerability report for CVE-2026-82023, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thimpress learnpress to 4.4.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a broken object-level authorization vulnerability in the LearnPress WordPress Plugin before version 4.4.6. Authenticated attackers with the Instructor role can add answers to quiz questions owned by other instructors by exploiting a missing ownership check. They can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to modify quiz content across courses they do not own.

Detection Guidance

This vulnerability requires checking WordPress plugin configurations and database entries. Inspect LearnPress plugin versions for outdated installations (pre-4.4.6). Review quiz question ownership and answer logs for unauthorized modifications by instructors. No direct network commands detect this; manual audit of WordPress admin panels and database queries is needed.

Impact Analysis

If you are an instructor using LearnPress, attackers could alter your quiz questions and answers without permission. This could lead to incorrect assessments, compromised course integrity, and reputational damage. For students, it may result in unfair evaluations or misleading educational content.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to educational content, potentially violating data integrity and access control requirements in GDPR or HIPAA. Persistent unauthorized changes to quiz content may lead to non-compliance with policies requiring accurate and secure handling of sensitive information.

Mitigation Strategies

Update the LearnPress WordPress Plugin to version 4.4.6 or later to address the broken object-level authorization vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82023. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart