Cross-Site Scripting Vulnerability in LearnPress by ThimPress
CVE-2025-67536
6.5MEDIUM
What is CVE-2025-67536?
An improper neutralization of input during web page generation in the ThimPress LearnPress plugin allows for stored Cross-Site Scripting (XSS) attacks. This vulnerability affects all versions from n/a to 4.2.9.4. Malicious users may exploit this flaw to inject arbitrary scripts into the web application, potentially compromising the security of users and their data.
Affected Version(s)
LearnPress <= n/a