WordPress · Learnpress · CVE-2026-86446
**Name of the Vulnerable Software and Affected Versions**
LearnPress versions prior to 4.4.7
**Description**
The plugin fails to restrict the correctness flags returned during the quiz answer verification process. This allows unauthenticated attackers to retrieve the correct answers for all options of a question, as well as the instructor's explanation, specifically for courses configured to be accessible without enrollment. This occurs via the `check-answer` REST endpoint.
**Recommendations**
Update to version 4.4.7 or later.