Executive brief
LearnPress is a WordPress plugin that creates and manages online learning platforms with courses, lessons, and quizzes. The vulnerability allows instructors to bypass ownership restrictions and modify quiz content (answers) in courses they do not own, compromising the integrity of quiz assessments across the platform.
Technical details
The vulnerability is a broken object-level authorization (CWE-863) flaw in the quiz answer insertion endpoint of LearnPress before version 4.4.6. The vulnerable code path fails to validate that the authenticated instructor owns the quiz question before accepting answer submissions, allowing attackers to supply arbitrary question identifiers and insert answers into quizzes across courses they lack authorization for. The attack requires authentication with the Instructor role and network access to the quiz answer API endpoint; no user interaction or elevated privileges are needed beyond the Instructor role. An attacker can persistently modify quiz answers, corrupting educational content and potentially affecting student grading and learning outcomes. A patch is available in version 4.4.6 and later.
Affected products
- ThimPress LearnPress before 4.4.6
Timeline
- 2026-09-03: disclosed