Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Revanth Matte

#44774of 56,326
6.4Total CVSS
Vulnerabilities · 1
PT-2026-87026
6.4
2026-09-08
Thimpress · Learnpress – Wordpress Lms Plugin For Create/Sell Online Courses · CVE-2026-12230
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout custom css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.