CVE-2026-86444: Unknown Learnpress
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who opens a crafted link, including a logged in administrator. Only sites running a classic, non-block are affected.
Affected products
- Unknown Learnpress: from 4.2.6.4, before 4.4.7 (fixed in 4.4.7)
Published 2026-09-16. Last modified 2026-09-17.