Impact
The LearnPress WordPress LMS plugin is vulnerable to a stored XSS flaw caused by insufficient sanitization of the 'layout_custom_css' parameter. This weakness (CWE‑79) means that an authenticated user with contributor‑level access or higher can persistently inject arbitrary web scripts that execute when a user visits a page rendering the custom CSS.
Affected Systems
WordPress sites that use LearnPress versions 4.3.9.1 or earlier are affected. The flaw exists in all versions up to and including 4.3.9.1 and is tied to the plugin’s layout_custom_css handling.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating a moderate severity and a moderate likelihood of exploitation. Because the EPSS score is not available and the CVE is not listed in the CISA KEV catalog, there is no current evidence of widespread exploitation. The likely attack vector is an authenticated user with contributor permissions, which is a relatively common role on many WordPress installations. The flaw would allow the attacker to inject client‑side scripts that could deface content, steal user‑session data, or perform phishing attempts against site visitors.
OpenCVE Enrichment