Cross-Site Scripting Vulnerability in ThimPress LearnPress Plugin
CVE-2025-49992
7.1HIGH
What is CVE-2025-49992?
The LearnPress Export Import plugin developed by ThimPress contains a vulnerability that allows for reflected cross-site scripting (XSS) attacks. This issue arises from improper neutralization of input during webpage generation, potentially allowing attackers to inject malicious scripts. Users of affected versions, specifically those earlier than or equal to 4.0.9, are encouraged to take immediate action to secure their applications.
Affected Version(s)
LearnPress Export Import <= n/a