Skip to main content
Vulnerability Database/CVE-2026-105397

CVE-2026-105397: LearnPress WordPress Plugin XSS Vulnerability

CVE-2026-105397 is a stored cross-site scripting vulnerability in LearnPress WordPress plugin that lets instructors inject malicious scripts via quiz fields. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-105397 Overview

CVE-2026-105397 is a stored cross-site scripting [CWE-79] vulnerability in the LearnPress plugin for WordPress through version 4.4.9.1. The flaw resides in the quiz question hint and explanation fields processed by the update_question AJAX handler. Authenticated users with the Instructor role can submit unsanitized payloads that persist in the course content. These payloads execute in the browser of every student who loads the affected quiz. The vulnerability affects LearnPress, a widely deployed learning management system (LMS) plugin for WordPress.

Critical Impact

Instructors can store JavaScript that executes in every student's session, enabling session theft, forced actions, and malware delivery across the course audience.

Affected Products

  • LearnPress plugin for WordPress versions through 4.4.9.1
  • WordPress sites running LearnPress with Instructor role accounts enabled
  • Any LMS deployment relying on the vulnerable update_question AJAX handler

Discovery Timeline

  • 2026-10-05 - CVE-2026-105397 published to the National Vulnerability Database (NVD)
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-105397

Vulnerability Analysis

The vulnerability is a stored cross-site scripting (XSS) flaw in LearnPress question editing. When an Instructor edits a quiz question, the frontend calls the update_question AJAX endpoint handled by inc/Ajax/EditQuestionAjax.php. The hint and explanation fields on each question are persisted to the database without sufficient output encoding or input sanitization. When a student later loads the quiz, those fields are rendered into the DOM and any embedded <script> or event-handler payload executes in the student's browser context.

Because execution occurs under the WordPress site origin, the payload inherits the authenticated student's session. An attacker can harvest session cookies, submit forms on the student's behalf, pivot to administrative actions if an administrator loads the quiz, or redirect the user to a credential-harvesting page. The attack scales to the entire audience of a course.

Root Cause

The root cause is missing sanitization of instructor-supplied rich text in the question hint and explanation fields prior to storage, combined with unescaped output when the quiz is rendered to students. The patch introduces the LearnPress\Helpers\Template helper into QuestionPostModel.php and bumps the EditQuestionAjax class to version 1.0.2, indicating centralized sanitization and templating of question content.

Attack Vector

Exploitation requires an authenticated account with the Instructor role on a vulnerable WordPress site. The attacker edits or creates a quiz question and injects JavaScript into the hint or explanation field through the update_question AJAX call. The payload persists in the database and triggers whenever a student opens the quiz, satisfying the user-interaction requirement of loading the lesson.

php
// Patch excerpt - inc/Ajax/EditQuestionAjax.php
 * This class handles the AJAX request to edit the curriculum of a course.
 *
 * @since 4.2.9
- * @version 1.0.0
+ * @version 1.0.2
 */

namespace LearnPress\Ajax;
php
// Patch excerpt - inc/Models/Question/QuestionPostModel.php
use Exception;
use LearnPress\Databases\QuestionAnswersDB;
use LearnPress\Filters\QuestionAnswersFilter;
+use LearnPress\Helpers\Template;
use LearnPress\Models\PostModel;
use LP_Cache;
use LP_Debug;

Source: GitHub Commit 9db279c

Detection Methods for CVE-2026-105397

Indicators of Compromise

  • Quiz question hint or explanation fields in the WordPress database containing <script>, onerror=, onload=, or javascript: strings.
  • Unexpected outbound requests from student browsers to attacker-controlled domains after loading a quiz page.
  • Edits to lp_question postmeta records authored by Instructor accounts shortly before anomalous student session activity.

Detection Strategies

  • Query the WordPress postmeta table for LearnPress question fields and flag entries containing HTML tags or JavaScript URI schemes.
  • Review web server access logs for POST requests to admin-ajax.php with the update_question action originating from Instructor accounts.
  • Monitor the browser console and Content Security Policy (CSP) violation reports on quiz pages for inline script blocks.

Monitoring Recommendations

  • Audit all Instructor account activity, especially new or recently promoted accounts, for question-editing events.
  • Enable WordPress audit logging to capture changes to quiz questions along with the author, timestamp, and payload size.
  • Alert on sudden spikes in authenticated student sessions issuing unusual XHR or fetch requests after quiz load.

How to Mitigate CVE-2026-105397

Immediate Actions Required

  • Upgrade LearnPress to the patched release that includes commit 9db279c0d9fd3993430bb9af158658282e9bcee1.
  • Audit all existing quiz questions for stored HTML or JavaScript in hint and explanation fields and remove malicious content.
  • Review the Instructor role roster and revoke access for accounts that are no longer required.

Patch Information

The vendor fix is published in the LearnPress GitHub commit 9db279c, which hardens EditQuestionAjax.php and introduces the LearnPress\Helpers\Template helper in QuestionPostModel.php. Full technical analysis is available in the VulnCheck Stored XSS Advisory and the upstream LearnPress Plugin Overview.

Workarounds

  • Temporarily restrict the Instructor role so only trusted users can create or edit quiz questions.
  • Deploy a Web Application Firewall (WAF) rule that blocks update_question AJAX requests containing script tags or JavaScript URI schemes.
  • Enforce a strict Content Security Policy on course and quiz pages to prevent inline script execution.
bash
# Example CSP header to block inline scripts on quiz pages
Header set Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.