Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thimpress
Thimpress learnpress – Wordpress Lms Plugin For Create And Sell Online Courses Wordpress Wordpress wordpress |
|
| Vendors & Products |
Thimpress
Thimpress learnpress – Wordpress Lms Plugin For Create And Sell Online Courses Wordpress Wordpress wordpress |
Tue, 14 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visitors, and uses that nonce as the only security gate for the `lp-load-ajax` AJAX dispatcher. The `delete_question_answer` action has no capability or ownership check. This makes it possible for unauthenticated attackers to delete any quiz answer option by sending a crafted POST request with a publicly available nonce. | |
| Title | LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-14T13:48:54.581Z
Reserved: 2026-03-17T20:45:25.774Z
Link: CVE-2026-4365
Updated: 2026-04-14T13:47:56.198Z
Status : Deferred
Published: 2026-04-14T02:16:05.767
Modified: 2026-04-22T20:23:16.350
Link: CVE-2026-4365
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:31:06Z