Impact
The LearnPress plugin contains a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation. An attacker who can inject malicious code into the plugin’s content or configuration fields can have the script executed in the browser of any user who views the affected page, potentially leading to session hijacking, defacement, or phishing attacks.
Affected Systems
WordPress installations that have the LearnPress plugin installed at any version from the earliest release through 4.2.9.4, inclusive. The vulnerability affects the ThimPress LearnPress product and applies to any website that utilizes the vulnerable plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score of less than 1% shows that the likelihood of exploitation is currently very low. This vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply crafted content that is stored within the plugin—likely through privileged content‑creation or plugin configuration interfaces—and then cause normal users to load that content in their browsers. No external network exploitation vector is described, so the exploit is expected to occur via the normal web application traffic that is already handled by the site.
OpenCVE Enrichment