WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / September 3, 2026

Vulnerability in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — CVE-2026-82023

MediumSeverity
CVSS 5.3
0.2%Estimated exploit probability
EPSS
70,000+ sitesInstalls
4.4.6Fixed in

What to do now

Update LearnPress – WordPress LMS Plugin for Create and Sell Online Courses to 4.4.6 or later.

Affected versions

  • Everything before 4.4.6

Affected: LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (plugin, learnpress)

Check: The plugin on wordpress.org / Our record for LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

What the vulnerability is

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts