Impact
LearnPress allows an authenticated user with the Instructor role to submit answer titles for quiz questions. The plugin stores that input without sanitization and later renders it directly as HTML. This flaw lets an attacker inject persistent JavaScript that will execute in the browsers of any user who views the affected quiz, including students, other instructors, or administrators. The injected code can steal credentials, perform actions in the victim’s context, or display malicious content, thereby compromising confidentiality, integrity, and availability of the learning environment.
Affected Systems
The vulnerability applies to the ThimPress LearnPress WordPress plugin in any WordPress installation using a version older than 4.4.6. Any site that has this plugin deployed and grants the Instructor role to a user is at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an authenticated user with the Instructor role, the attack vector is inferred to be an insider or privileged credential compromise scenario. Exploitation also depends on the attacker being able to add a new answer title to a quiz. The EPSS score is unavailable, but the documented impact and privilege requirement suggest a moderate likelihood of targeted exploitation under the right conditions.
OpenCVE Enrichment