OSV 1.4.0 · unreviewed · 修改于 2026-09-04 02:31
发布时间
2026-09-04 02:31
GitHub 审查时间
—
NVD 发布时间
2026-09-04 02:17
源文件
advisories/unreviewed/2026/09/GHSA-f3vp-h5hg-9gmp/GHSA-f3vp-h5hg-9gmp.json
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing ownership check on the question answer insert path. Attackers can supply arbitrary question identifiers during answer insertion, bypassing instructor-boundary restrictions to persistently modify quiz content across courses they do not own.
该公告没有提供结构化的受影响软件包信息。