CVE-2026-105397

Source
https://cve.org/CVERecord?id=CVE-2026-105397
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105397.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105397
Published
2026-10-05T15:11:23Z
Modified
2026-10-08T10:30:32Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation
Details

LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105397.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "4.4.9.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "last_affected": "4.4.9.1"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "fixed": "4.4.9.1"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/learnpress/learnpress

Affected ranges

Type
GIT
Repo
https://github.com/learnpress/learnpress
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

2.*
2.0.0-beta.1
2.0.6
2.0.9
2.1.0
2.1.3
2.1.4
2.1.5.2
2.1.5.3
2.1.6
3.*
3.2.1
3.2.2
v1.*
v1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105397.json"