Executive brief
LearnPress is a WordPress plugin for creating and managing online courses with quizzes. The plugin's quiz checking feature was exposing correct answers and instructor explanations to unauthenticated users on courses that allow access without enrollment, allowing attackers to trivially obtain all quiz answers without taking the course.
Technical details
The vulnerability is an information disclosure flaw in the LearnPress WordPress plugin's check-answer REST endpoint. The plugin failed to properly restrict or filter the response data returned when validating quiz answers, allowing unauthenticated attackers to call the endpoint and receive not only which answers are correct, but also the instructor's explanations. This affects courses configured to be accessible without enrollment. The flaw was present in versions 4.4.3 through 4.4.6 and is fixed in version 4.4.7.
Affected products
- LearnPress LearnPress 4.4.3 to 4.4.6
Timeline
- 2026-09-15: disclosed
- 2026-09-17: patched: Fixed in version 4.4.7