Insecure Direct Object Reference in WP Courses LMS Plugin by WordPress
CVE-2026-10630
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-10630?
The WP Courses LMS plugin for WordPress is susceptible to an Insecure Direct Object Reference due to inadequate validation on the 'resultID' parameter. This vulnerability allows authenticated attackers with custom-level access or higher to access other users' quiz answers and scores. By manipulating the incrementing resultID value through the wpcq_get_quiz_result AJAX action, attackers can bypass security and retrieve sensitive data. The plugin's access control is dependent solely on a nonce check, which is insufficiently protective, exposing key functionality to all logged-in users on the front end.
Affected Version(s)
WP Courses LMS β Online Courses Builder, eLearning Courses, Courses Solution, Education Courses 0 <= 3.2.29