WP Security CheckVulnerability data as of October 6, 2026

Vulnerability alerts / October 5, 2026

Vulnerability in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — CVE-2026-105397

MediumSeverity
CVSS 5.1
—Estimated exploit probability
EPSS
70,000+ sitesInstalls
Not publishedFixed in

What to do now

No fix has been published yet. Consider disabling LearnPress – WordPress LMS Plugin for Create and Sell Online Courses for now, or moving to an alternative.

Affected versions

  • Everything up to and including 4.4.9.1

Affected: LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (plugin, learnpress)

Check: The plugin on wordpress.org / Our record for LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

What the vulnerability is

LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts