{"id":"CVE-2026-105397","title":"LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields","summary":"LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor rol…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"ThimPress","product":"LearnPress","affected":["LearnPress <= 4.4.9.1"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T16:17:12.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105397","references":[{"url":"https://github.com/LearnPress/learnpress/commit/9db279c0d9fd3993430bb9af158658282e9bcee1","label":"disclosure@vulncheck.com"},{"url":"https://plugins.svn.wordpress.org/learnpress/tags/4.4.9.1/assets/src/apps/js/frontend/quiz/components/questions/question.js","label":"disclosure@vulncheck.com"},{"url":"https://plugins.svn.wordpress.org/learnpress/tags/4.4.9.1/inc/Ajax/EditQuestionAjax.php","label":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/learnpress/","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/learnpress-wordpress-plugin-through-4.4.9.1-stored-xss-via-quiz-question-hint-and-explanation","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T16:25:58.411Z","slug":"CVE-2026-105397","body":"## Overview\n\nLearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}