CVE-2026-86445: LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax
The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress WordPress plugin before 4.4.7 otherwise keeps non-public.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker can exploit the affected administrative template handler; no user account or capabilities are required.
What information can be exposed?
An attacker can retrieve the text, identifier, and type of every published quiz question. The vulnerable handler also supports keyword searches across those questions.
Which sites are affected?
Sites using LearnPress versions before 4.4.7 are affected if they have published quiz questions. The issue exposes content that LearnPress otherwise treats as non-public.