CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105397
MEDIUMCVSS 5.4NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question A
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog