MEDIUM 5.3 NVD
CVE-2026-82023
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
References
- https://wordpress.org/plugins/learnpress/#developers
- https://www.vulncheck.com/advisories/learnpress-wordpress-plugin-broken-object-level-autho
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-03 via NVD.
vulnfeed aggregates 7617 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.