Junglewise Threat Intelligence

CVE-2026-48865: ThimPress LearnPress reflected XSS

CVE-2026-48865 · Severity: high · CVSS 7.1 · Published 2026-06-01

Technologies: ThimPress LearnPress. Vendors: ThimPress.

Executive brief

LearnPress is a popular WordPress plugin used to create and manage online courses and learning management systems. A security flaw allows attackers to trick users into clicking a malicious link that executes unauthorized code in their browser. This can lead to the theft of login sessions, unauthorized website changes, or the redirection of students and administrators to malicious websites.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the ThimPress LearnPress plugin for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw affects versions up to and including 4.3.6. An unauthenticated remote attacker can exploit this by sending a specially crafted link to a user; if the user clicks the link, the malicious script is executed within the context of the user's session. This can lead to session hijacking, sensitive data theft, or unauthorized administrative actions if the victim is a site administrator. The issue is resolved in version 4.3.7.

Affected products

  • ThimPress LearnPress up to 4.3.6

Timeline

  • 2026-05-11: disclosed: Reported by VanTastic via Patchstack
  • 2026-06-01: advisory: NVD and Patchstack published advisory details
  • 2026-06-01: patched: Version 4.3.7 released to address the vulnerability

References

Related threats