Stored Cross-Site Scripting Vulnerability in LearnPress WordPress Plugin by Eduma
CVE-2026-82024
5.1MEDIUM
What is CVE-2026-82024?
The LearnPress WordPress plugin by Eduma is vulnerable to a stored cross-site scripting (XSS) issue that affects versions prior to 4.4.6. This vulnerability allows authenticated users with the Instructor role to inject and store malicious JavaScript payloads within quiz question answer title fields. By submitting unsanitized input, attackers can exploit this vulnerability to execute malicious scripts in the browsers of anyone who accesses the affected quiz question. This includes students, other instructors, and administrators, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
LearnPress 0 < 4.4.6