CVE-2026-4365Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visitors, and uses that nonce as the only security gate for the `lp-load-ajax` AJAX dispatcher. The `delete_question_answer` action has no capability or ownership check. This makes it possible for unauthenticated attackers to delete any quiz answer option by sending a crafted POST request with a publicly available nonce.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 6 mentions (2026-04-14); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
02356Mentions · 2026-04-14: 6Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 6Technical Details · 2026-04-17: 104-1404-1504-1704-18
Signal classification3 categories
Disclosure
666.7%
General
222.2%
Patch
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-146
Disclosure5Patch1
2026-04-151
General1
2026-04-171
Disclosure1
2026-04-181
General1
Full discourse9 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-27303 2 - CVE-2026-34197 3 - CVE-2026-5194 4 - CVE-2026-4365 5 - CVE-2026-34621 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The text merely lists several trending CVEs without offering any technical or actionable information.

    00010174
    1.7K followersView on X
  • z3n@zench4n
    Disclosure

    Data integrity remains a major concern. CVE-2026-4365 in WordPress highlights how missing capabilities lead to unauthorized deletion. In agentic systems, ensure your RAG pipelines and vector databases have strict, least-privilege access controls.

    Post summary

    The post announces CVE-2026-4365, noting that missing capabilities in WordPress allow unauthorized deletion, without mentioning exploits or patches.

    1000011
    1.5K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4365 — CVSS 9.1/10 █████████░ The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/0j4dxiIc3i

    Post summary

    CVE-2026-4365 exposes LearnPress plugin to unauthorized data deletion due to a missing capability check, with a critical severity of CVSS 9.1/10, and a patch is now available.

    1000039
    23 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4365 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4365 #CVE-2026-4365 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/V5enwXd9au

    Post summary

    The tweet announces CVE‑2026‑4365 as a critical Wordpress vulnerability with a CVSS score of 9.1, but provides no PoC, exploit, patch, or detailed technical information.

    0000033
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4365 The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all vers… https://www.cve.org/CVERecord?id=CVE-2026-4365

    Post summary

    The text announces a CVE‑2026‑4365 vulnerability in LearnPress that allows unauthorized data deletion due to a missing capability check on the delete_question_answer() function.

    0000070
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4365 Unauthorized Data Deletion in LearnPress Plugin for WordPress Up to 4.3.2.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4365

    Post summary

    The post announces CVE-2026-4365, a vulnerability that permits unauthorized data deletion in LearnPress WordPress plugin versions up to 4.3.2.8.

    0000030
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4365: CRITICAL] WordPress LearnPress plugin up to version 4.3.2.8 has a vulnerability allowing unauthorized data deletion through a missing capability check in `delete_question_answer()`, using a pub...#cve,CVE-2026-4365,#cybersecurity https://cvefind.com/CVE-2026-4365

    Post summary

    The tweet announces a critical vulnerability in WordPress LearnPress plugin that enables unauthorized data deletion due to a missing capability check in the delete_question_answer() function.

    0000048
    620 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-4365 The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on th… CVSS 9.1 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-4365 #WordPress #CyberSecurity #InfoSec

    Post summary

    A critical vulnerability (CVE-2026‑4365) in the LearnPress WordPress plugin is disclosed with a CVSS of 9.1 and no patch yet, but no PoC, exploit code, or evidence of active exploitation.

    000000
    144 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4365: LearnPress <= 4.3.2.8 - Missing A... Publicly exposed wp_rest nonce + missing authz checks = unauthenticated quiz answer nuking via AJAX - classic WordPress ... https://zerodaysignal.com/vulnerability/CVE-2026-4365 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new CVE-2026-4365 affecting LearnPress versions up to 4.3.2.8 allows unauthenticated deletion of quiz answers via AJAX because of missing authorization checks, but no PoC, exploit code, patch, or active exploitation reports are included.

    0000059
    218 followersView on X

Explore more