CVE-2026-105397
LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz.
| CWE | CWE-79 |
| Vendor | thimpress |
| Product | learnpress |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for thimpress learnpress
Be the first to know when new medium vulnerabilities affecting thimpress learnpress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
ThimPress / LearnPress
0 โค 4.4.9.1
References
github.com: https://github.com/LearnPress/learnpress/commit/9db279c0d9fd3993430bb9af158658282e9bcee1 plugins.svn.wordpress.org: https://plugins.svn.wordpress.org/learnpress/tags/4.4.9.1/inc/Ajax/EditQuestionAjax.php plugins.svn.wordpress.org: https://plugins.svn.wordpress.org/learnpress/tags/4.4.9.1/assets/src/apps/js/frontend/quiz/components/questions/question.js wordpress.org: https://wordpress.org/plugins/learnpress/ vulncheck.com: https://www.vulncheck.com/advisories/learnpress-wordpress-plugin-through-4.4.9.1-stored-xss-via-quiz-question-hint-and-explanation
Credits
HunterSploit