๐Ÿ” CVE Alert

CVE-2026-12970

HIGH 7.1

LearnPress < 4.4.1 - Reflected XSS via c_search

CVSS Score
7.1
EPSS Score
0.2%
EPSS Percentile
5th

The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.

Vendor unknown
Product learnpress
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown learnpress

Be the first to know when new high vulnerabilities affecting unknown learnpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / LearnPress
0 < 4.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d0a2780f-ab13-4bb8-935d-2aeba1de12d2/

Credits

Meher Sudhakar Abbireddi WPScan