PatchSiren cyber security CVE debrief
CVE-2026-86446 LearnPress CVE debrief
CVE-2026-86446 LearnPress WordPress plugin vulnerability allows unauthenticated attackers to obtain correct quiz answers and instructor explanations without enrolling in courses. This issue arises from the plugin's failure to restrict correctness flags for quiz answers, potentially impacting course integrity and confidentiality. Defenders should verify and restrict access to course content, especially for unauthenticated users, and monitor course activity for suspicious quiz answer submissions.
- Vendor
- LearnPress
- Product
- LearnPress
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders of WordPress installations using the LearnPress plugin, especially those with public-facing courses, should verify and restrict access to course content. They should also monitor course activity for suspicious quiz answer submissions and review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
CVE-2026-86446 allows unauthenticated attackers to obtain correct quiz answers and instructor explanations in LearnPress WordPress plugin, impacting course integrity and confidentiality.
- Unauthenticated access to sensitive course content
- Potential for unauthorized quiz answer submissions
- Risk of compromised course integrity
- Need for verification of LearnPress plugin version
Technical summary
The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling. This issue impacts course integrity and confidentiality, emphasizing the need for defenders to verify and restrict access to course content, especially for unauthenticated users, and to monitor course activity.
Defensive priority
Verify and restrict access to course content, especially for unauthenticated users.
Recommended defensive actions
- Verify LearnPress plugin version and update to 4.4.7 or later
- Restrict access to course content for unauthenticated users
- Monitor course activity for suspicious quiz answer submissions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The LearnPress WordPress plugin before 4.4.7 does not restrict correctness flags for quiz answers, allowing unauthenticated attackers to obtain correct answers and instructor explanations. This issue was identified through source-provided CVE metadata and NIST NVD vulnerability assessment. To verify, defenders should check the LearnPress plugin version and restrict access to course content for unauthenticated users.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86446 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86446
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86446 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86446
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/20004b72-69f5-406f-b1e6-e88f6f6ffae7/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.