CVE-2026-12970
LearnPress < 4.4.1 - Reflected XSS via c_search
CVSS Score
7.1
EPSS Score
0.2%
EPSS Percentile
5th
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.
| Vendor | unknown |
| Product | learnpress |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown learnpress
Be the first to know when new high vulnerabilities affecting unknown learnpress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / LearnPress
0 < 4.4.1
References
Credits
Meher Sudhakar Abbireddi WPScan