Sceawere

Vulnerability Detail

CVE-2026-105397UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LearnPress Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
ThimPress
Product
LearnPress
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T16:17:12.650Z",
  "pubdate": "2026-10-05T16:17:12.650Z",
  "executiveSummary": "LearnPress plugin versions through 4.4.9.1 are susceptible to a stored cross-site scripting (XSS) vulnerability.\nThe vulnerability allows authenticated users with the Instructor role to inject arbitrary JavaScript payloads into quiz question hint and explanation fields.\nThese malicious scripts are executed within the browser sessions of students viewing the compromised quiz content.\nThis flaw represents a significant security risk, as successful exploitation enables session hijacking, unauthorized actions performed on behalf of the student, and potential information disclosure.\nThe vulnerability originates from insufficient input sanitization during the processing of quiz-related data via the update_question AJAX handler.\nExploitation requires the attacker to possess Instructor-level privileges within the WordPress environment.",
  "technicalDetails": "The vulnerability exists within the LearnPress plugin's data processing logic, specifically affecting the handling of quiz component attributes.\nThe root cause is identified as the inadequate sanitization and validation of user-supplied input submitted via the update_question AJAX handler. When an instructor updates a quiz question, the plugin fails to strip or encode malicious HTML and script tags present in the 'hint' and 'explanation' fields before persisting them to the database.\nThe attack flow proceeds as follows: An authenticated Instructor initiates an AJAX request to the update_question function, embedding a crafted JavaScript payload within the metadata of a quiz question. Because the backend does not sanitize this input, the payload is stored verbatim in the database associated with the quiz content.\nWhen a student accesses the quiz, the LearnPress plugin fetches the stored data and renders the hint or explanation content directly into the Document Object Model (DOM) of the student's browser session. Consequently, the injected JavaScript executes in the context of the student's current session.\nBecause the execution occurs within the context of the student's browser, the attacker can leverage the script to capture sensitive session cookies, perform unauthorized API requests, or redirect users to malicious external domains. This cross-site scripting vector persists until the quiz content is corrected, meaning every student who views the affected question will be exposed to the payload.\nThis vulnerability is restricted to users with Instructor privileges; however, in environments where multiple instructors collaborate or where instructor accounts are compromised, the impact is critical. The exposure is limited to the web application's frontend where quiz information is displayed to students. The failure to implement proper output encoding, such as using WordPress-native functions like wp_kses_post() or esc_html(), directly facilitates this exploitation vector."
}
CVE-2026-105397: LearnPress Stored XSS Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere