CVE-2026-86446: Unknown Learnpress

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling.

Affected products

  • Unknown Learnpress: from 4.4.3, before 4.4.7 (fixed in 4.4.7)

Published 2026-09-17. Last modified 2026-09-18.