OVERVIEW: CVE-2026-4365 affects the LearnPress WordPress plugin through version 4.3.2.8. The vulnerability stems from multiple security failures: the plugin exposes a WordPress REST nonce to unauthenticated users in public HTML, uses this nonce as the sole authentication mechanism for an AJAX dispatcher, and fails to implement capability checks on the delete_question_answer() function. This combination allows attackers to delete any quiz answer option without authentication. SEVERITY: The vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring no special access, low complexity, and no user interaction. The attack has high integrity and availability impact, enabling unauthorized destruction of quiz data. While the CVSS score is critical, the EPSS score of 0.0007 suggests relatively lower prevalence in active exploitation compared to other known vulnerabilities. EXPLOITATION STATUS: The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and does not appear on active threat lists. No publicly available exploitation data or significant community attention is documented at this time. However, given the straightforward nature of the attack requiring only a crafted POST request and publicly available nonce, organizations running affected versions should prioritize patching to versions beyond 4.3.2.8 to prevent opportunistic exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Thimpress | LearnPress – WordPress LMS Plugin For Create And Sell Online Courses | >= 0, <= 4.3.2.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.