CVE-2026-10630
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom-level access and above, to read any other user's quiz answers and scores by enumerating the incrementing resultID value via the wpcq_get_quiz_result AJAX action. The only access control on this endpoint is a nonce check (wpc_nonce) that is exposed to every logged-in user on the frontend, providing no meaningful authorization barrier.
What this means for your business
- An attacker can use it remotely, over a network, with an ordinary user login, and without anyone at your company clicking anything.
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 4.3 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N- Weakness
- CWE-639
- Assigned by
- security@wordfence.com
Dates
- Published
- 2026-08-25
- Last modified
- 2026-08-26
- Sources
- NVD
References
- https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.28/classes/WPCQ_Ajax.php#L28
- https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.28/classes/WPCQ_Ajax.php#L87
- https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.28/classes/WPCQ_Ajax.php#L91
- https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.29/classes/WPCQ_Ajax.php#L28
- https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.29/classes/WPCQ_Ajax.php#L87
- https://plugins.trac.wordpress.org/browser/wp-courses/tags/3.2.29/classes/WPCQ_Ajax.php#L91
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3660496%40wp-courses&new=3660496%40wp-courses
- https://www.wordfence.com/threat-intel/vulnerabilities/id/83936cda-e868-44f6-be5d-f26086bc4688?source=cve