LearnPress Missing Authorization Vulnerability Allowing Unauthenticated Deletion of Quiz Answers

Vulnerability

A vulnerability exists in the LearnPress WordPress plugin, in all versions through 4.3.2.8, allowing unauthorized deletion of quiz answers. This issue arises from a lack of capability checks in the 'delete_question_answer()' function. The plugin exposes a 'wp_rest' nonce in public frontend HTML, which is used as the sole security measure for the 'lp-load-ajax' AJAX dispatcher. Without any capability or ownership checks, unauthenticated attackers can delete quiz answer options by sending a POST request with the publicly available nonce.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of quiz answer options, potentially disrupting the integrity of quiz data.

Remediation

Users are advised to update the LearnPress WordPress plugin to version 4.3.3 or a newer patched version.

Added: Apr 14, 2026, 2:23 AM
Updated: Apr 14, 2026, 2:23 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
8.2
remediation
7.7
relevance
5.9
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.