Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82023— LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert

Quick assessment

Affected
ThimPress LearnPress
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LearnPress WordPress 插件在 4.4.6 版本之前存在一个对象级授权失效(broken object-level authorization)漏洞。该漏洞允许拥有“讲师”(Instructor)角色的已认证攻击者,通过利用答案插入路径中缺失的属主检查,向其他讲师所属的测验题目中添加答案。攻击者可以在插入答案时提供任意的题目标识符,从而绕过讲师边界限制,对其未拥有的课程中的测验内容进行永久性修改。

CVSS 4.3 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
ThimPress LearnPress < 4.4.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82023

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert
Source: CVE Program / CVE List V5
Vulnerability Description
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ThimPress LearnPress 0 ~ 4.4.6 -

II. Public POCs for CVE-2026-82023

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82023

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82023 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82023

No comments yet


Leave a comment