Impact
The LearnPress plugin fails to sanitize or escape the orderby query string, enabling an attacker to insert arbitrary JavaScript that is reflected back into the page. This reflected DOM‑based XSS can execute client‑side code when a victim follows a crafted link. The vulnerability is exploitable by unauthenticated actors but requires the target user to interact with the affected page.
Affected Systems
WordPress sites running the LearnPress LMS plugin version 4.4.7 or earlier are affected. The issue exists in every local or hosted deployment that includes these plugin versions and is triggered when the orderby parameter is used in administrative or front‑end pages.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity with a medium impact on confidentiality and integrity of the user context. The exploit requires only a crafted link and does not require authentication or system privileges, making it highly accessible to attackers on the internet. EPSS data is unavailable and the vulnerability is not listed in CISA's KEV catalog, but the client‑side nature of the flaw still poses a significant threat if not remediated promptly.
OpenCVE Enrichment