CVE-2026-12970: The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri
infovulnerability
security
Summary
The LearnPress WordPress plugin before version 4.4.1 has a vulnerability where it doesn't properly clean a search parameter before putting it into HTML code, allowing reflected cross-site scripting (XSS, where attackers inject malicious code that runs in a user's browser). This vulnerability can execute in the browsers of logged-in instructors or administrators who are tricked into clicking a specially crafted link.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
July 20, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12970
First tracked: July 20, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%