WP Vulnerability WatchVulnerability data as of September 9, 2026

Vulnerability alerts / September 8, 2026

Vulnerability in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — CVE-2026-12230

MediumSeverity
CVSS 6.4
Estimated exploit probability
EPSS
70,000+ sitesInstalls
4.4.0Fixed in

What to do now

Update LearnPress – WordPress LMS Plugin for Create and Sell Online Courses to 4.4.0 or later.

Affected versions

  • Everything up to and including 4.3.9.1

Affected: LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (plugin, learnpress)

Check: The plugin on wordpress.org / Our record for LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

What the vulnerability is

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts