Sceawere
Vulnerability Detail
CVE-2026-104670UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
LearnPress Unauthenticated Reflected XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- ThimPress
- Product
- LearnPress
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:39.317Z",
"pubdate": "2026-10-06T09:17:39.317Z",
"executiveSummary": "This vulnerability is an Unauthenticated Cross-Site Scripting (XSS) flaw identified in LearnPress versions 4.4.9 and below.\nThe vulnerability resides in the application's handling of user-supplied input, which fails to undergo proper sanitization or encoding before being reflected back to the user's browser.\nSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary JavaScript within the context of a victim's browser session.\nThe risk implications are critical, as the impact includes the potential for session hijacking, credential theft, redirection to malicious domains, and unauthorized actions performed on behalf of authenticated users, including administrators.\nBecause the vulnerability is unauthenticated, exploitation requires no prior access or interaction with the system, significantly increasing the potential attack surface.\nOrganizations using vulnerable versions of LearnPress are at high risk until the software is updated or appropriate input filtering mechanisms are implemented.",
"technicalDetails": "The vulnerability is a Reflected XSS condition stemming from improper neutralization of input data within the LearnPress plugin framework.\nThe root cause of this flaw is the insecure processing of HTTP GET or POST parameters by the vulnerable component. The plugin fails to validate or sanitize these parameters against a whitelist of expected characters, nor does it perform output encoding when rendering the data in the server's HTML response.\nThe exploitation flow begins when an unauthenticated attacker crafts a malicious URI containing a payload designed to bypass existing security filters and trigger JavaScript execution in the victim's browser. When a user—such as an administrator—clicks on this link, the LearnPress plugin reflects the malicious script payload directly into the DOM.\nOnce rendered, the payload executes within the security context of the origin where the LearnPress plugin is installed. This bypasses the Same-Origin Policy (SOP), allowing the injected script to access sensitive information such as document.cookie, localStorage, or perform actions via background XHR requests without the user's consent.\nBecause the vulnerability does not require authentication, it is exposed over the network to any remote actor capable of reaching the web server. There are no privilege requirements, as the injection point is accessible prior to the application's authorization checks.\nIn a post-exploitation scenario, the attacker can leverage the XSS to perform session token theft. If the victim has an active administrative session, the attacker may use the XSS payload to programmatically inject additional malicious administrative users, modify site configurations, or inject persistent backdoors into other site components, effectively leading to full site compromise.\nThe affected versions are LearnPress <= 4.4.9. The vulnerability is highly dependent on the reflection point within the plugin's code, where user-supplied input is echoed to the page without adequate context-aware encoding (e.g., HTML entity encoding for body content or attribute encoding for HTML tag attributes).\nTechnical indicators suggest that the flaw may exist in frontend template files or AJAX handling functions that fail to invoke WordPress sanitization functions like sanitize_text_field() or output escaping functions such as esc_html() and esc_js()."
}