Stored Cross-Site Scripting Vulnerability in LearnPress WordPress LMS Plugin
CVE-2026-4333

6.4MEDIUM

What is CVE-2026-4333?

The LearnPress WordPress LMS Plugin allows authenticated users with Contributor-level access and above to exploit a vulnerability caused by insufficient input sanitization and output escaping on the 'skin' attribute of the learn_press_courses shortcode. This flaw permits the injection of arbitrary web scripts that execute on user access, potentially compromising the integrity and security of the affected pages.

Affected Version(s)

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 0 <= 4.3.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Djaidja Moundjid
.