CVE-2026-82023: LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenti
mediumvulnerability
security
Summary
LearnPress, a WordPress plugin for online courses, has a broken object-level authorization vulnerability (a flaw where the system doesn't properly check if a user owns something before letting them modify it) in versions before 4.4.6. Instructors can trick the system into adding quiz answers to questions they don't own by supplying fake question IDs, allowing them to change quiz content in courses that aren't theirs.
Solution / Mitigation
Update LearnPress WordPress Plugin to version 4.4.6 or later.
Vulnerability Details
CVSS Score
4.3(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
September 3, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82023
First tracked: September 3, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 95%