Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz. | |
| Title | LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation | |
| First Time appeared |
Thimpress
Thimpress learnpress |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Thimpress
Thimpress learnpress |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T15:11:23.468Z
Reserved: 2026-10-05T10:56:23.833Z
Link: CVE-2026-105397
No data.
Status : Received
Published: 2026-10-05T16:17:12.650
Modified: 2026-10-05T16:17:12.650
Link: CVE-2026-105397
No data.
OpenCVE Enrichment
Updated: 2026-10-05T17:00:23Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')