PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10623 pressprimer CVE debrief

The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin for WordPress is vulnerable to Insecure Direct Object Reference. This CVE, published on June 18, 2026, allows authenticated attackers with custom-level access and above to modify or delete quiz rules belonging to other teachers. The vulnerability exists in all versions up to, and including, 2.3.0 due to missing validation on a user-controlled key. The CVSS score for this vulnerability is 4.3, indicating a Medium severity. Users of the PressPrimer Quiz plugin should update to a patched version as soon as possible to prevent unauthorized tampering of quiz structures.

Vendor
pressprimer
Product
PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-18
Original CVE updated
2026-06-18
Advisory published
2026-06-18
Advisory updated
2026-06-18

Who should care

Administrators and users of the PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin for WordPress, especially those with custom-level access and above, should be aware of this vulnerability. Additionally, educators and institutions using the plugin for quiz management should prioritize updating the plugin to prevent potential misuse.

Technical summary

The PressPrimer Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) in all versions up to and including 2.3.0. The vulnerability is caused by missing validation on the 'rule_id' parameter, which is user-controlled. This allows authenticated attackers with custom-level access and above to modify or delete quiz rules belonging to other teachers. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N, indicating a Medium severity with a score of 4.3. The CWE associated with this vulnerability is CWE-639.

Defensive priority

High

Recommended defensive actions

  • Update the PressPrimer Quiz plugin to a version beyond 2.3.0 as soon as possible.
  • Restrict access to the plugin's quiz management features to trusted users only.
  • Implement additional monitoring to detect and respond to potential unauthorized changes to quiz rules.
  • Consider using a Web Application Firewall (WAF) to help detect and prevent exploitation attempts.
  • Regularly review and update user access levels and permissions within the plugin.
  • Educate users with custom-level access and above about the importance of secure quiz management practices.

Evidence notes

The information provided is based on data from the National Vulnerability Database (NVD) and Wordfence security research. The CVE record and NVD detail pages provide official information about the vulnerability. Additional references from Wordfence offer further context and technical details about the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10623 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10623

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10623 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10623

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/PressPrimer/pressprimer-quiz/commit/1795687

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/pressprimer-quiz/tags/2.1.0/includes/api/class-ppq-rest-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/pressprimer-quiz/tags/2.1.0/includes/api/class-ppq-rest-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/pressprimer-quiz/tags/2.1.0/includes/api/class-ppq-rest-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/pressprimer-quiz/tags/2.1.0/includes/api/class-ppq-rest-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/pressprimer-quiz/tags/2.1.0/includes/api/class-ppq-rest-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/pressprimer-quiz/tags/2.1.0/includes/api/class-ppq-rest-controller.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.