Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12970 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-07-21 | 7.1 High |
| The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link. | ||||
| CVE-2026-8383 | 2 Learnpress, Wordpress | 2 Learnpress, Wordpress | 2026-06-26 | 5.3 Medium |
| The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request | ||||
Page 1 of 1.