Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4365

32
FAUCET Score

OVERVIEW: CVE-2026-4365 affects the LearnPress WordPress plugin through version 4.3.2.8. The vulnerability stems from multiple security failures: the plugin exposes a WordPress REST nonce to unauthenticated users in public HTML, uses this nonce as the sole authentication mechanism for an AJAX dispatcher, and fails to implement capability checks on the delete_question_answer() function. This combination allows attackers to delete any quiz answer option without authentication. SEVERITY: The vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring no special access, low complexity, and no user interaction. The attack has high integrity and availability impact, enabling unauthorized destruction of quiz data. While the CVSS score is critical, the EPSS score of 0.0007 suggests relatively lower prevalence in active exploitation compared to other known vulnerabilities. EXPLOITATION STATUS: The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and does not appear on active threat lists. No publicly available exploitation data or significant community attention is documented at this time. However, given the straightforward nature of the attack requiring only a crafted POST request and publicly available nonce, organizations running affected versions should prioritize patching to versions beyond 4.3.2.8 to prevent opportunistic exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
ThimpressLearnPress – WordPress LMS Plugin For Create And Sell Online Courses
>= 0, <= 4.3.2.8CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.87%
Probability of exploitation in next 30 days
EPSS Percentile
55.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0087 is in the 39th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/learnpress/trunk/inc/Ajax/AbstractAjax.php
plugins.trac.wordpress.org / browser/learnpress/trunk/inc/Ajax/EditQuestionAjax.php
plugins.trac.wordpress.org / browser/learnpress/trunk/inc/class-lp-assets.php
wordfence.com / threat-intel/vulnerabilities/id/021bd566-1663-46ba-a616-ab554b691cbb