Executive brief
The WP Courses LMS WordPress plugin is an online learning management system used to create and deliver educational courses. An authentication bypass vulnerability allows any logged-in user to view other users' quiz answers and test scores by exploiting insufficient access controls on quiz result retrieval, potentially exposing sensitive student performance data.
Technical details
The plugin contains an Insecure Direct Object Reference (IDOR) vulnerability in the wpcq_get_quiz_result AJAX action handler, where the 'resultID' parameter lacks proper authorization validation. Although a nonce check (wpc_nonce) is present, this nonce is exposed to all logged-in frontend users, providing no meaningful access control. Authenticated attackers with custom-level access and above can enumerate incrementing resultID values to retrieve arbitrary quiz attempts, answers, and scores belonging to other users. The vulnerability affects all versions up to and including 3.2.29 and is network-accessible to any authenticated user of the WordPress installation.
Affected products
- WP Courses WP Courses LMS up to and including 3.2.29
Timeline
- 2026-08-25: disclosed