WordPress Plugin Vulnerabilities

LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax

Description

The plugin does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the plugin otherwise keeps non-public.

Proof of Concept

Affects Plugins

Fixed in 4.4.7

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-14 (about 1 day ago)

Other