Reflected DOM-Based Cross-Site Scripting in LearnPress β WordPress LMS Plugin
CVE-2026-92538
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92538?
The LearnPress LMS Plugin for WordPress is susceptible to a reflected DOM-based cross-site scripting vulnerability through the 'orderby' parameter. This issue stems from inadequate input sanitization and output escaping, potentially allowing unauthenticated attackers to inject arbitrary web scripts. If a user is tricked into clicking a malicious link, these scripts could execute within their browser, posing a significant security risk. It is crucial for users of the affected versions to apply necessary updates and ensure their environments are secure.
Affected Version(s)
LearnPress β WordPress LMS Plugin for Create and Sell Online Courses 0 <= 4.4.7