CVE-2026-82023

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 18:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-82023

Mitre link : CVE-2026-82023

CVE.ORG link : CVE-2026-82023


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization