Stored Cross-Site Scripting Vulnerability in LearnPress Plugin for WordPress
CVE-2026-105397
5.1MEDIUM
What is CVE-2026-105397?
The LearnPress plugin for WordPress, up to version 4.4.9.1, suffers from a stored cross-site scripting vulnerability that allows authenticated instructors to inject malicious scripts through quiz question hint and explanation fields. When exploited, attackers in the instructor role can submit unsanitized payloads via the update_question AJAX handler, enabling the execution of scripts in the browsers of students taking the affected quizzes. This can lead to unauthorized actions or information theft, posing a significant threat to user data integrity.
Affected Version(s)
LearnPress 0 <= 4.4.9.1