---
id: CVE-2026-82023
title: >-
  LearnPress WordPress Plugin before 4.4.6 contains a broken object-level
  authorization vulnerability that allows authenticated attackers with the
  Instructor role to add answers to quiz questions owned by other instructors by
  exploiting a …
summary: >-
  LearnPress WordPress Plugin before 4.4.6 contains a broken object-level
  authorization vulnerability that allows authenticated attackers with the
  Instructor role to add answers to quiz questions owned by other instructors by
  exploiting a …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82023'
references:
  - url: 'https://wordpress.org/plugins/learnpress/#developers'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/learnpress-wordpress-plugin-broken-object-level-authorization-via-quiz-answer-insert
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00295
epssPercentile: 0.19701
ingestedAt: '2026-09-05T20:44:37.663Z'
---

## Overview

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
