---
id: CVE-2026-86445
title: >-
  The LearnPress  WordPress plugin before 4.4.7 does not check the user's
  capabilities in one of its administrative template handlers, allowing
  unauthenticated attackers to retrieve the text, identifier and type of every
  published quiz que…
summary: >-
  The LearnPress  WordPress plugin before 4.4.7 does not check the user's
  capabilities in one of its administrative template handlers, allowing
  unauthenticated attackers to retrieve the text, identifier and type of every
  published quiz que…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: LearnPress
affected:
  - LearnPress >= 4.2.9 < 4.4.7
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:51.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86445'
references:
  - url: 'https://wpscan.com/vulnerability/df2d1ebb-ac1d-430d-8e99-7d88df47cf5b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:18:16.516973Z'
epss: 0.00345
epssPercentile: 0.25277
ingestedAt: '2026-09-16T06:51:06.253Z'
---

## Overview

The LearnPress  WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress  WordPress plugin before 4.4.7 otherwise keeps non-public.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
