WordPress Plugin Vulnerabilities

LearnPress < 4.4.1 - Reflected XSS via c_search

Description

The plugin does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link.

Proof of Concept

Affects Plugins

Fixed in 4.4.1

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes

Timeline

Publicly Published
2026-06-29 (about 22 days ago)
Added
2026-06-29 (about 21 days ago)
Last Updated
2026-06-29 (about 21 days ago)

Other