CVE-2026-82024: LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated
Summary
The LearnPress WordPress plugin before version 4.4.6 has a stored cross-site scripting vulnerability (XSS, a type of attack where malicious code is injected into a website and stored so it runs in users' browsers). Instructors can exploit this by submitting unfiltered code into quiz answer title fields, which then executes when students, other instructors, or administrators view the quiz. This allows attackers to run arbitrary JavaScript (code that performs actions) in victims' browsers without their knowledge.
Solution / Mitigation
Update LearnPress WordPress Plugin to version 4.4.6 or later.
Vulnerability Details
5.4(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
network
low
low
required
September 3, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82024
First tracked: September 3, 2026 at 08:07 PM
Classified by LLM (prompt v3) · confidence: 95%