Impact
The vulnerability exists in the LearnPress WordPress plugin version 4.4.6 and earlier. A user‑supplied value passed through the 'skin' query parameter is not escaped before being inserted into an HTML attribute on a publicly viewable page. This omission allows an unauthenticated attacker to embed arbitrary JavaScript in URLs that, when opened by any visitor—including privileged administrators—execute in the victim’s browser, leading to data theft, session hijacking, or defacement. The weakness is a classic reflected cross‑site scripting flaw (CWE‑79).
Affected Systems
Affected systems are WordPress installations that use the LearnPress plugin before version 4.4.7. Any site running the classic UI flow that exposes the public course page with the 'skin' parameter is vulnerable. The vulnerability applies regardless of user role and is not limited to administrative accounts.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a very low probability of exploit at the present time, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is a simple crafted link; no authentication or exploitation of additional code paths is required. The impact is limited to the victim’s browser session, but an attacker could steal credentials, inject malware, or deface the site from within the user’s context.
OpenCVE Enrichment