Insecure Direct Object Reference in WP Courses LMS Plugin by WordPress
CVE-2026-10630

4.3MEDIUM

What is CVE-2026-10630?

The WP Courses LMS plugin for WordPress is susceptible to an Insecure Direct Object Reference due to inadequate validation on the 'resultID' parameter. This vulnerability allows authenticated attackers with custom-level access or higher to access other users' quiz answers and scores. By manipulating the incrementing resultID value through the wpcq_get_quiz_result AJAX action, attackers can bypass security and retrieve sensitive data. The plugin's access control is dependent solely on a nonce check, which is insufficiently protective, exposing key functionality to all logged-in users on the front end.

Affected Version(s)

WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses 0 <= 3.2.29

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vapour
.