Impact
The LearnPress WordPress plugin before version 4.4.1 fails to escape a user-supplied search parameter, causing it to be reflected into an HTML attribute exactly as received. This flaw enables a reflected cross‑site scripting attack that runs arbitrary JavaScript in the context of any logged‑in instructor or administrator who opens a crafted link. The vulnerability is limited to the victim’s session, allowing the attacker to access session data, hijack the user’s identity or perform actions on behalf of the user, but it does not provide direct system compromise or affect data of unauthenticated users.
Affected Systems
All WordPress sites that host the LearnPress plugin in a version earlier than 4.4.1 are vulnerable. The issue is independent of site size or user count; any installation using a vulnerable plugin version will be susceptible when a privileged user follows a malicious link.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high risk level. An EPSS score of less than 1% reflects a very low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a logged‑in instructor or administrator to open a specially crafted link, typically delivered via social engineering or phishing. Successful exploitation results in arbitrary JavaScript execution within the victim’s browser session, which can lead to session hijacking, credential theft, or unauthorized actions performed under the victim’s privileges.
OpenCVE Enrichment