Stored Cross-Site Scripting Vulnerability in LearnPress Plugin for WordPress
CVE-2026-105397

5.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105397?

The LearnPress plugin for WordPress, up to version 4.4.9.1, suffers from a stored cross-site scripting vulnerability that allows authenticated instructors to inject malicious scripts through quiz question hint and explanation fields. When exploited, attackers in the instructor role can submit unsanitized payloads via the update_question AJAX handler, enabling the execution of scripts in the browsers of students taking the affected quizzes. This can lead to unauthorized actions or information theft, posing a significant threat to user data integrity.

Affected Version(s)

LearnPress 0 <= 4.4.9.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HunterSploit
.