Broken Object-Level Authorization in LearnPress Plugin for WordPress
CVE-2026-82023

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-82023?

The LearnPress WordPress Plugin, prior to version 4.4.6, is susceptible to a broken object-level authorization vulnerability. This flaw allows authenticated users with the Instructor role to manipulate quiz questions owned by other instructors. By bypassing missing ownership checks within the answer insertion path, these users can insert arbitrary question identifiers, leading to unauthorized modifications of quiz content across different courses. This vulnerability poses significant security risks, as it undermines the integrity of educational content managed within the platform.

Affected Version(s)

LearnPress 0 < 4.4.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yll Berisha
VulnCheck
.