Vulnerability Description
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/learnpress/#developers
- https://www.vulncheck.com/advisories/learnpress-wordpress-plugin-broken-object-l
FAQ
What is CVE-2026-82023?
CVE-2026-82023 is a vulnerability with a CVSS score of 4.3 (MEDIUM). LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned ...
How severe is CVE-2026-82023?
CVE-2026-82023 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82023?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.