CVE-2026-92538 Overview
CVE-2026-92538 is a Reflected DOM-Based Cross-Site Scripting [CWE-79] vulnerability in the LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. The flaw affects all plugin versions up to and including 4.4.7. The vulnerability stems from insufficient input sanitization and output escaping of the orderby parameter. Unauthenticated attackers can inject arbitrary web scripts that execute in a victim's browser when the victim clicks a crafted link. Successful exploitation requires user interaction but can lead to session hijacking, administrative action abuse, or redirection to attacker-controlled infrastructure.
Critical Impact
Unauthenticated attackers can execute arbitrary JavaScript in the context of an authenticated administrator's browser session by tricking them into clicking a crafted URL.
Affected Products
- LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
- All plugin versions up to and including 4.4.7
- WordPress sites running the LearnPress LMS plugin
Discovery Timeline
- 2026-10-03 - CVE-2026-92538 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-92538
Vulnerability Analysis
The vulnerability resides in LearnPress administrative components that handle the orderby request parameter. The parameter value flows from HTTP request input through PHP-rendered output and into client-side JavaScript initialization logic without adequate sanitization or output encoding. Attacker-controlled content is reflected into the page and reaches a DOM sink that interprets it as script, enabling execution in the context of the victim's browser session on the vulnerable WordPress site.
Because the sink is DOM-based, the payload may execute without the server inspecting the final rendered content. The scope is marked as changed, reflecting the ability to affect resources beyond the vulnerable component, such as other browser contexts under the same origin.
Root Cause
The root cause is improper neutralization of input during web page generation [CWE-79]. According to the referenced source files, user-controlled data flows through inc/admin/views/search-author-field.php, inc/admin/class-lp-admin-assets.php, and inc/class-lp-helper.php, and is consumed by the client-side script assets/src/js/admin/init-tom-select.js. Neither the server-side rendering nor the client-side consumer applies sufficient escaping before the value is placed into a context where it can be parsed as HTML or JavaScript.
Attack Vector
Exploitation is network-based and requires no authentication. An attacker crafts a URL that includes a malicious orderby parameter value and delivers it to a victim through phishing, social engineering, or a malicious third-party site. When the victim, typically a WordPress administrator or privileged user, visits the link, the payload is reflected into the page and executed in the browser. The attacker can then issue requests on behalf of the victim, exfiltrate session cookies not marked HttpOnly, or manipulate the administrative interface.
No verified public proof-of-concept code is available. For technical specifics, consult the Wordfence Vulnerability Report and the referenced plugin source files such as the WordPress LearnPress Author Search View.
Detection Methods for CVE-2026-92538
Indicators of Compromise
- HTTP requests to LearnPress administrative endpoints containing suspicious orderby parameter values with HTML tags, JavaScript URI schemes, or encoded script content.
- Referrer logs showing WordPress administrators arriving at LearnPress admin pages from external untrusted domains.
- Unexpected outbound requests from administrator browser sessions to attacker-controlled domains shortly after visiting a LearnPress admin page.
Detection Strategies
- Deploy web application firewall rules that flag orderby parameter values containing <, >, script, javascript:, onerror=, or percent-encoded equivalents on LearnPress admin URLs.
- Review access logs for query strings targeting LearnPress components with payload patterns indicative of reflected XSS probes.
- Correlate administrator session activity with inbound referrers from external domains to identify potential phishing-driven exploitation.
Monitoring Recommendations
- Enable verbose logging on the WordPress admin interface and forward logs to a centralized analytics platform for query-string analysis.
- Alert on anomalous administrator account activity such as new user creation, plugin installation, or configuration changes shortly after admin page loads with suspicious parameters.
- Monitor browser telemetry or content security policy violation reports from administrator workstations to catch inline script execution attempts.
How to Mitigate CVE-2026-92538
Immediate Actions Required
- Update the LearnPress plugin to a version newer than 4.4.7 as soon as a patched release is available from the vendor.
- If no patched version is available, temporarily deactivate the LearnPress plugin on production sites or restrict administrator access to the LearnPress admin interface.
- Instruct administrators and privileged users to avoid clicking LearnPress admin links received from external sources, email, or chat.
Patch Information
No fixed version is identified in the available advisory data at the time of writing. Monitor the Wordfence Vulnerability Report and the LearnPress plugin page on the WordPress Plugin Directory for the official patched release. Apply the update across all affected WordPress sites and verify the plugin version post-upgrade.
Workarounds
- Deploy a web application firewall rule to block or sanitize requests where the orderby parameter on LearnPress admin endpoints contains HTML or JavaScript metacharacters.
- Enforce a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted origins, reducing the impact of reflected XSS execution.
- Require administrators to use dedicated browser profiles or isolated sessions for WordPress management to limit cross-context data exposure.
# Example ModSecurity rule to block script-like payloads in the orderby parameter
SecRule ARGS:orderby "@rx (?i)(<script|javascript:|onerror=|onload=|%3Cscript)" \
"id:1092538,phase:2,deny,status:403,log,\
msg:'CVE-2026-92538 LearnPress orderby XSS attempt blocked'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.