{"api_version":"1","generated_at":"2026-09-16T07:44:41+00:00","cve":"CVE-2026-86445","urls":{"html":"https://cve.report/CVE-2026-86445","api":"https://cve.report/api/cve/CVE-2026-86445.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-86445","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-86445"},"summary":{"title":"LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax","description":"The LearnPress  WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress  WordPress plugin before 4.4.7 otherwise keeps non-public.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:34","updated_at":"2026-09-16 06:16:34"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/df2d1ebb-ac1d-430d-8e99-7d88df47cf5b/","name":"https://wpscan.com/vulnerability/df2d1ebb-ac1d-430d-8e99-7d88df47cf5b/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-86445","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86445","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"LearnPress","version":"affected 4.2.9 4.4.7 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Karthik Ramakrishnan","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"LearnPress","vendor":"Unknown","versions":[{"lessThan":"4.4.7","status":"affected","version":"4.2.9","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Karthik Ramakrishnan"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The LearnPress  WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress  WordPress plugin before 4.4.7 otherwise keeps non-public."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:15.158Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/df2d1ebb-ac1d-430d-8e99-7d88df47cf5b/"}],"source":{"discovery":"EXTERNAL"},"title":"LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-86445","datePublished":"2026-09-16T06:00:15.158Z","dateReserved":"2026-09-07T12:51:45.155Z","dateUpdated":"2026-09-16T06:00:15.158Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:34","lastModifiedDate":"2026-09-16 06:16:34","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"86445","Ordinal":"1","Title":"LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure vi","CVE":"CVE-2026-86445","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"86445","Ordinal":"1","NoteData":"The LearnPress  WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz question on the site, along with a keyword search over them, which is content the LearnPress  WordPress plugin before 4.4.7 otherwise keeps non-public.","Type":"Description","Title":"LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure vi"}]}}}