CVE-2026-4365
Last modified
CVE-2026-4365 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visitors, and uses that nonce as the only security gate for the `lp-load-ajax` AJAX dispatcher. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visitors, and uses that nonce as the only security gate for the `lp-load-ajax` AJAX dispatcher. The `delete_question_answer` action has no capability or ownership check. This makes it possible for unauthenticated attackers to delete any quiz answer option by sending a crafted POST request with a publicly available nonce.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4365?
How severe is CVE-2026-4365?
How do I fix CVE-2026-4365?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43638Bitwarden Server prior to v2026.4.1 contains a missing autho…5.4
- CVE-2026-43639Bitwarden Server prior to v2026.4.0 contains a missing autho…9.1
- CVE-2026-4364IBM Verify Identity Access Container 11.0 through 11.0.2 and…5.4
- CVE-2026-43640Bitwarden Server prior to v2026.4.1 does not require master-…8.6
- CVE-2026-43644podinfo through 6.11.2 contains a reflected cross-site scrip…6.1
- CVE-2026-43646Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2026-43652A permissions issue was addressed with additional restrictio…7.5
- CVE-2026-43653The issue was addressed with improved memory handling. This …6.2
- CVE-2026-43654The issue was addressed with improved memory handling. This …7.5
- CVE-2026-43655An out-of-bounds read was addressed with improved bounds che…7.3
- CVE-2026-43656An out-of-bounds write issue was addressed with improved inp…7.3
- CVE-2026-43658The issue was addressed with improved memory handling. This …7.5
Are you affected by CVE-2026-4365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
