Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-4365 — AI Deep Analysis Summary

CVSS 9.1 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: LearnPress plugin (v4.3.2.8 & older) has a critical flaw in `delete_question_answer`. <br>⚠️ **Consequences**: Attackers can delete **any** quiz answer options without permission.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **Missing Authorization Check** (CWE-862). <br>🔍 **Flaw**: The function lacks proper capability verification. It trusts the request blindly, allowing unauthorized actions. 🚫

Q3Who is affected? (Versions/Components)

👥 **Affected**: WordPress Plugin **LearnPress**. <br>📦 **Version**: **4.3.2.8 and earlier**. <br>🏢 **Vendor**: ThimPress. If you use this LMS plugin, you are at risk! ⚠️

Q4What can hackers do? (Privileges/Data)

💀 **Attacker Power**: Delete **arbitrary** quiz answer options. <br>🔓 **Privileges**: **Unauthenticated** access required. No login needed! <br>📉 **Impact**: High Integrity & Availability loss. Courses become unusable. 📉

Q5Is exploitation threshold high? (Auth/Config)

📉 **Threshold**: **LOW**. <br>🔑 **Auth**: **None** required (PR:N). <br>🌐 **Network**: Remote (AV:N). <br>🖱️ **UI**: None needed (UI:N). Easy to exploit! 🚀

Q6Is there a public Exp? (PoC/Wild Exploitation)

📜 **Public Exp?**: **No specific PoC** listed in data. <br>🔍 **Status**: References exist (Wordfence, WP Trac), but no ready-to-use exploit code is provided here. Be cautious! 🕵️‍♂️

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: Scan for **LearnPress** plugin. <br>📊 **Version**: Check if version ≤ **4.3.2.8**. <br>🛠️ **Tool**: Use WP vulnerability scanners or check plugin admin panel.…

Q8Is it fixed officially? (Patch/Mitigation)

✅ **Fixed?**: Yes, implied by version cutoff. <br>🔄 **Action**: Update LearnPress to **latest version** immediately. <br>📦 **Vendor**: ThimPress released the fix. Don't wait! 🏃‍♂️

Q9What if no patch? (Workaround)

🚧 **No Patch?**: Disable the plugin temporarily. <br>🛡️ **Mitigation**: Restrict access to `/wp-admin/` via IP whitelist. <br>🔒 **Backup**: Secure database backups before any changes. Safety first! 🛡️

Q10Is it urgent? (Priority Suggestion)

🔥 **Urgency**: **HIGH**. <br>⚡ **Priority**: **Critical**. <br>🚨 **Reason**: Unauthenticated, Remote, High Impact. Fix **NOW** to prevent course data destruction! 🚑