PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86446 LearnPress CVE debrief

CVE-2026-86446 LearnPress WordPress plugin vulnerability allows unauthenticated attackers to obtain correct quiz answers and instructor explanations without enrolling in courses. This issue arises from the plugin's failure to restrict correctness flags for quiz answers, potentially impacting course integrity and confidentiality. Defenders should verify and restrict access to course content, especially for unauthenticated users, and monitor course activity for suspicious quiz answer submissions.

Vendor
LearnPress
Product
LearnPress
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders of WordPress installations using the LearnPress plugin, especially those with public-facing courses, should verify and restrict access to course content. They should also monitor course activity for suspicious quiz answer submissions and review compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

CVE-2026-86446 allows unauthenticated attackers to obtain correct quiz answers and instructor explanations in LearnPress WordPress plugin, impacting course integrity and confidentiality.

  • Unauthenticated access to sensitive course content
  • Potential for unauthorized quiz answer submissions
  • Risk of compromised course integrity
  • Need for verification of LearnPress plugin version

Technical summary

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling. This issue impacts course integrity and confidentiality, emphasizing the need for defenders to verify and restrict access to course content, especially for unauthenticated users, and to monitor course activity.

Defensive priority

Verify and restrict access to course content, especially for unauthenticated users.

Recommended defensive actions

  • Verify LearnPress plugin version and update to 4.4.7 or later
  • Restrict access to course content for unauthenticated users
  • Monitor course activity for suspicious quiz answer submissions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The LearnPress WordPress plugin before 4.4.7 does not restrict correctness flags for quiz answers, allowing unauthenticated attackers to obtain correct answers and instructor explanations. This issue was identified through source-provided CVE metadata and NIST NVD vulnerability assessment. To verify, defenders should check the LearnPress plugin version and restrict access to course content for unauthenticated users.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86446 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86446

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86446 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86446

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.