Junglewise Threat Intelligence

CVE-2026-12970: LearnPress WordPress plugin reflected XSS in c_search parameter

CVE-2026-12970 · Severity: info · CVSS 7.1 · Published 2026-07-20

Technologies: ThimPress LearnPress. Vendors: ThimPress.

Executive brief

LearnPress is a popular WordPress plugin used to create and sell online courses. A security flaw in the plugin allows attackers to execute malicious scripts in the browser of a site administrator or instructor. To succeed, an attacker must trick the victim into clicking a specially crafted link, which could lead to unauthorized actions being performed on the website or the theft of sensitive session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the LearnPress WordPress plugin before version 4.4.1. The issue stems from the 'c_search' parameter not being properly escaped before being reflected into an HTML attribute. An unauthenticated remote attacker can exploit this by tricking a logged-in instructor or administrator into clicking a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or administrative actions. The vulnerability is fixed in version 4.4.1.

Affected products

  • LearnPress LearnPress < 4.4.1

Timeline

  • 2026-06-29: disclosed: Publicly published by WPScan
  • 2026-06-29: patched: Fixed in version 4.4.1
  • 2026-07-20: advisory: NVD publication date

References

Related threats