Refine your search
2 vulnerabilities found for WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses by hookandhook
CVE-2026-10630 (GCVE-0-2026-10630)
Vulnerability from cvelistv5
Published
2026-08-25 01:26
Modified
2026-08-25 18:10
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Summary
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom-level access and above, to read any other user's quiz answers and scores by enumerating the incrementing resultID value via the wpcq_get_quiz_result AJAX action. The only access control on this endpoint is a nonce check (wpc_nonce) that is exposed to every logged-in user on the frontend, providing no meaningful authorization barrier.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| hookandhook | WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses |
Version: 0 ≤ 3.2.29 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-10630",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:09:49.886228Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:10:00.099Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WP Courses LMS \u2013 Online Courses Builder, eLearning Courses, Courses Solution, Education Courses",
"vendor": "hookandhook",
"versions": [
{
"lessThanOrEqual": "3.2.29",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Vapour"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WP Courses LMS \u2013 Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the \u0027resultID\u0027 parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom-level access and above, to read any other user\u0027s quiz answers and scores by enumerating the incrementing resultID value via the wpcq_get_quiz_result AJAX action. The only access control on this endpoint is a nonce check (wpc_nonce) that is exposed to every logged-in user on the frontend, providing no meaningful authorization barrier."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "CWE-639 Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T01:26:43.510Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/83936cda-e868-44f6-be5d-f26086bc4688?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.29/classes/WPCQ_Ajax.php#L91"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.29/classes/WPCQ_Ajax.php#L87"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.29/classes/WPCQ_Ajax.php#L28"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.28/classes/WPCQ_Ajax.php#L91"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.28/classes/WPCQ_Ajax.php#L87"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.28/classes/WPCQ_Ajax.php#L28"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026old=3660496%40wp-courses\u0026new=3660496%40wp-courses"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-06-05T13:13:00.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-08-24T13:26:34.000Z",
"value": "Disclosed"
}
],
"title": "WP Courses LMS \u003c= 3.2.29 - Insecure Direct Object Reference to Authenticated (Custom+) Sensitive Information Disclosure via \u0027resultID\u0027 Parameter"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-10630",
"datePublished": "2026-08-25T01:26:43.510Z",
"dateReserved": "2026-06-02T14:52:11.530Z",
"dateUpdated": "2026-08-25T18:10:00.099Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-12172 (GCVE-0-2024-12172)
Vulnerability from cvelistv5
Published
2024-12-12 05:24
Modified
2026-04-08 17:01
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-862 - Missing Authorization
Summary
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user's metadata which can be levereged to block an administrator from accessing their site when wp_capabilities is set to 0.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| hookandhook | WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses |
Version: 0 ≤ 3.2.21 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-12172",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-12-12T14:49:38.341103Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-12-12T14:50:35.267Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WP Courses LMS \u2013 Online Courses Builder, eLearning Courses, Courses Solution, Education Courses",
"vendor": "hookandhook",
"versions": [
{
"lessThanOrEqual": "3.2.21",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thanh Nam Tran"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WP Courses LMS \u2013 Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user\u0027s metadata which can be levereged to block an administrator from accessing their site when wp_capabilities is set to 0."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-08T17:01:26.703Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/760e999e-cac9-493f-9737-ad0cf055c880?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=\u0026sfph_mail=\u0026reponame=\u0026old=3203679%40wp-courses\u0026new=3203679%40wp-courses\u0026sfp_email=\u0026sfph_mail="
}
],
"timeline": [
{
"lang": "en",
"time": "2024-12-11T00:00:00.000Z",
"value": "Disclosed"
}
],
"title": "WP Courses LMS \u2013 Online Courses Builder, eLearning Courses, Courses Solution, Education Courses \u003c= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2024-12172",
"datePublished": "2024-12-12T05:24:21.551Z",
"dateReserved": "2024-12-04T15:20:15.836Z",
"dateUpdated": "2026-04-08T17:01:26.703Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}