{"id":"CVE-2026-105397","summary":"LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint and Explanation","details":"LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz.","modified":"2026-10-08T10:30:32.652364575Z","published":"2026-10-05T15:11:23.468Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105397.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"4.4.9.1"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"last_affected":"4.4.9.1"}],"source":"CPE_FIELD"},{"source":"DESCRIPTION","extracted_events":[{"fixed":"4.4.9.1"}]}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://wordpress.org/plugins/learnpress/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105397.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105397"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/learnpress-wordpress-plugin-through-4.4.9.1-stored-xss-via-quiz-question-hint-and-explanation"},{"type":"FIX","url":"https://github.com/LearnPress/learnpress/commit/9db279c0d9fd3993430bb9af158658282e9bcee1"},{"type":"ARTICLE","url":"https://plugins.svn.wordpress.org/learnpress/tags/4.4.9.1/assets/src/apps/js/frontend/quiz/components/questions/question.js"},{"type":"ARTICLE","url":"https://plugins.svn.wordpress.org/learnpress/tags/4.4.9.1/inc/Ajax/EditQuestionAjax.php"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/learnpress/learnpress","events":[{"introduced":"0"},{"fixed":"9db279c0d9fd3993430bb9af158658282e9bcee1"}],"database_specific":{"source":"REFERENCES"}}],"versions":["3.2.2","3.2.1","2.1.6","2.1.5.3","2.1.5.2","2.1.4","2.1.3","2.1.0","2.0.9","2.0.6","2.0.0-beta.1","v1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105397.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}