CVE-2026-104670 Overview
CVE-2026-104670 is an unauthenticated Cross-Site Scripting (XSS) vulnerability affecting the LearnPress WordPress plugin in versions 4.4.9 and earlier. LearnPress is a learning management system (LMS) plugin widely deployed on WordPress sites to deliver online courses. The flaw allows remote attackers to inject malicious client-side scripts without authentication. Successful exploitation requires user interaction, typically through a crafted link or page visit. The weakness is tracked under CWE-79: Improper Neutralization of Input During Web Page Generation.
Critical Impact
Attackers can execute arbitrary JavaScript in the context of a victim's browser session, enabling session theft, credential harvesting, defacement, and redirection to attacker-controlled infrastructure.
Affected Products
- LearnPress WordPress plugin versions <= 4.4.9
- WordPress sites running vulnerable LearnPress installations
- Any site exposing LearnPress course or user-facing endpoints to the public internet
Discovery Timeline
- 2026-10-06 - CVE-2026-104670 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-104670
Vulnerability Analysis
The vulnerability is a reflected or stored Cross-Site Scripting flaw in the LearnPress plugin. User-supplied input is rendered back into HTML responses without sufficient output encoding or input sanitization. Because the vulnerability requires no authentication, any unauthenticated attacker can craft a payload and deliver it to a victim. The scope change in the vulnerability metric indicates that successful execution can affect resources beyond the vulnerable component, including the hosting WordPress site and the authenticated user's session. User interaction is required, meaning the victim must click a crafted URL or load an attacker-controlled resource.
Root Cause
The root cause is improper neutralization of input during web page generation [CWE-79]. LearnPress <= 4.4.9 fails to apply context-appropriate escaping on at least one input parameter before including it in the HTML response. WordPress sanitization helpers such as esc_html(), esc_attr(), and wp_kses() were not applied consistently in the affected code path. Specific affected parameters and sinks are documented in the Patchstack advisory.
Attack Vector
An attacker crafts a URL or form submission containing JavaScript payloads targeting the vulnerable LearnPress endpoint. The attacker distributes the link through phishing, social media, or injected content on third-party sites. When a victim visits the link, the server reflects the payload into the response or renders previously stored content. The browser executes the attacker's script under the origin of the WordPress site. If the victim is an authenticated administrator, the attacker can leverage the session to perform privileged actions, including plugin installation or user creation.
Detection Methods for CVE-2026-104670
Indicators of Compromise
- Web server access logs containing <script>, onerror=, onload=, or javascript: strings in LearnPress query parameters or POST bodies
- Unexpected administrative accounts, plugins, or options modifications on WordPress sites running LearnPress
- Outbound requests from browser sessions to unknown external domains after visiting LearnPress course pages
- Referrer chains showing users arriving at LearnPress endpoints from shortened or suspicious URLs
Detection Strategies
- Inspect HTTP request parameters directed at LearnPress endpoints for encoded or raw script payloads and HTML event handlers
- Monitor WordPress audit logs for privilege changes, option updates, or new users correlated with LearnPress page visits
- Deploy a Web Application Firewall (WAF) with signatures tuned to detect reflected and stored XSS patterns against WordPress plugins
Monitoring Recommendations
- Centralize WordPress, web server, and WAF logs in a SIEM for correlation across request, session, and administrative activity
- Alert on CSP (Content Security Policy) violation reports originating from LearnPress-hosted pages
- Track browser extension and endpoint telemetry for credential theft or session cookie exfiltration following LearnPress visits
How to Mitigate CVE-2026-104670
Immediate Actions Required
- Identify every WordPress site running the LearnPress plugin and determine the installed version
- Upgrade LearnPress to a version released after 4.4.9 that remediates CVE-2026-104670
- Rotate credentials and invalidate active sessions for WordPress administrators who may have visited crafted URLs
- Review WordPress audit logs for unauthorized changes made during the exposure window
Patch Information
Refer to the Patchstack advisory for LearnPress for the fixed version and remediation details. Apply the vendor update through the WordPress plugin manager or by replacing the plugin files with the patched release. Confirm the installed version reports higher than 4.4.9 after the update.
Workarounds
- Deploy WAF rules to block requests containing script tags, event handler attributes, and javascript: URIs targeting LearnPress endpoints
- Enforce a strict Content Security Policy that disallows inline script execution and restricts script sources to trusted origins
- Restrict access to LearnPress administrative and course endpoints by IP allowlist where feasible until the plugin is patched
- Disable or remove the LearnPress plugin on sites where it is not actively used
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.