CVE-2026-86444: Unknown Learnpress

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who opens a crafted link, including a logged in administrator. Only sites running a classic, non-block are affected.

Affected products

  • Unknown Learnpress: from 4.2.6.4, before 4.4.7 (fixed in 4.4.7)

Published 2026-09-16. Last modified 2026-09-17.