CVE-2026-104670: WordPress LearnPress plugin <= 4.4.9 - Cross Site Scripting (XSS) vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
Affected Software
1 affected component
thimpress LearnPress<=4.4.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LearnPress pluginto a version that resolves this vulnerability.Fixed in 4.4.9.1
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a LearnPress or WordPress account to attempt exploitation. User interaction is required for the attack to succeed.
2
Which LearnPress versions are affected?
LearnPress versions 4.4.9 and earlier are identified as affected. The provided data does not identify a fixed version.
3
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels. The CVSS vector also indicates the impact can extend beyond the vulnerable component's security scope.