CVE-2026-86446: The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is c
infovulnerability
security
Summary
The LearnPress WordPress plugin (a tool that helps create online courses) versions before 4.4.7 has a security flaw where it reveals whether quiz answers are correct or incorrect without checking if the person taking the quiz should have access to that information. This allows anyone, even without logging in, to figure out the right answer to every quiz question and read the instructor's explanations on courses that don't require enrollment.
Solution / Mitigation
Update the LearnPress WordPress plugin to version 4.4.7 or later.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 17, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86446
First tracked: September 17, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 95%