Loading market data...
← Back to CVE feed

CVE-2026-82023

MEDIUM CVSS 4.3 View on NVD ↗

Description

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Published: Sep 03, 2026 18:17 UTC Modified: Sep 03, 2026 18:17 UTC