Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-3225: CWE-862 Missing Authorization in thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

0
Medium
VulnerabilityCVE-2026-3225cvecve-2026-3225cwe-862
Published: Mon Mar 23 2026 (03/23/2026, 22:25:40 UTC)
Source: CVE Database V5
Vendor/Project: thimpress
Product: LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Description

CVE-2026-3225 is a medium-severity vulnerability in the LearnPress WordPress LMS plugin that allows authenticated users with Subscriber-level access or higher to delete quiz question answers without proper authorization. The flaw arises from a missing capability check in the delete_question_answer() function, where the REST nonce is verified but user permissions are not. This enables unauthorized modification of quiz content, potentially disrupting online courses. The vulnerability affects all versions up to 4. 3. 2. 8 and does not impact confidentiality or availability but compromises data integrity. There are no known exploits in the wild, and no patches have been released yet. Organizations using LearnPress for online education should urgently review user roles and restrict access to trusted users. Monitoring and applying updates once available is critical to prevent misuse.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 03/24/2026, 00:06:59 UTC

Technical Analysis

The vulnerability identified as CVE-2026-3225 affects the LearnPress – WordPress LMS Plugin, a widely used plugin for creating and selling online courses on WordPress sites. The issue stems from a missing authorization check (CWE-862) in the delete_question_answer() function within the EditQuestionAjax class. Although the plugin verifies a valid wp_rest nonce via the AbstractAjax::catch_lp_ajax() dispatcher, it fails to perform a current_user_can() capability check before allowing deletion of quiz question answers. Additionally, the QuestionAnswerModel::delete() method only enforces minimum answer counts but does not validate user permissions. Consequently, any authenticated user with Subscriber-level access or higher can delete answer options from any quiz question on the site, leading to unauthorized modification of course content. This vulnerability affects all versions up to and including 4.3.2.8. The CVSS v3.1 base score is 4.3 (medium), reflecting the ease of exploitation (network attack vector, low attack complexity, privileges required, no user interaction) and the limited impact on integrity without affecting confidentiality or availability. No known exploits have been reported in the wild, and no official patches are currently available. The flaw primarily threatens the integrity of quiz data, potentially undermining the reliability of assessments and course quality.

Potential Impact

The primary impact of this vulnerability is on the integrity of online course content managed via the LearnPress plugin. Unauthorized deletion of quiz answers can disrupt assessments, degrade the learning experience, and potentially cause loss of trust in the educational platform. While confidentiality and availability remain unaffected, the ability for low-privileged users to alter quiz content could be exploited for sabotage or to manipulate course outcomes. Organizations relying on LearnPress for e-learning, certification, or training may face reputational damage and operational disruption. The scope includes any WordPress site using vulnerable versions of LearnPress, which could be significant given the plugin's popularity in the online education sector. Although no exploits are known in the wild, the vulnerability's low complexity and network accessibility make it a credible risk if weaponized.

Mitigation Recommendations

To mitigate this vulnerability, organizations should immediately audit user roles and permissions within WordPress, ensuring that only trusted users have Subscriber-level or higher access. Restricting user registrations and enforcing strict role assignments can reduce the attack surface. Implementing Web Application Firewalls (WAFs) with custom rules to detect and block suspicious AJAX requests targeting the delete_question_answer() endpoint may provide temporary protection. Site administrators should monitor plugin updates closely and apply patches as soon as they are released by the vendor. In the absence of official patches, consider temporarily disabling quiz answer editing features or replacing LearnPress with alternative LMS plugins that enforce proper authorization checks. Additionally, regular backups of course data will facilitate recovery in case of unauthorized modifications. Security teams should also review logs for unusual deletion activity and alert on anomalous behavior related to quiz content management.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Wordfence
Date Reserved
2026-02-25T19:03:11.576Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 69c1d4a9f4197a8e3ba0b47f

Added to database: 3/24/2026, 12:02:49 AM

Last enriched: 3/24/2026, 12:06:59 AM

Last updated: 3/24/2026, 5:20:12 AM

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses