PatchSiren cyber security CVE debrief
CVE-2026-12970 LearnPress CVE debrief
CVE-2026-12970 is a Reflected Cross-Site Scripting vulnerability in LearnPress WordPress plugin before 4.4.1. The plugin does not escape a search parameter before reflecting it into an HTML attribute, potentially allowing attackers to inject malicious scripts. This vulnerability executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted link. Users should review and apply vendor remediation if available.
- Vendor
- LearnPress
- Product
- LearnPress
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-20
Who should care
Users of LearnPress WordPress plugin before version 4.4.1 should be aware of this Reflected Cross-Site Scripting vulnerability. System administrators, security teams, and users with elevated privileges in WordPress environments are particularly impacted. They should assess their exposure, apply vendor remediation if available, and monitor for suspicious activity.
Technical summary
The LearnPress WordPress plugin before 4.4.1 does not properly sanitize user input, specifically a search parameter, before reflecting it into an HTML attribute. This oversight leads to a Reflected Cross-Site Scripting vulnerability, which can be exploited by attackers through crafted links. Successful exploitation requires user interaction, typically a logged-in instructor or administrator opening the malicious link.
Defensive priority
Medium
Recommended defensive actions
- Inventory and verify LearnPress WordPress plugin version.
- Apply vendor remediation if available.
- Monitor for suspicious activity.
- Implement compensating controls.
- Review and update asset inventory for affected systems.
- Track exceptions and retest remediated assets.
Evidence notes
Evidence is limited. Official CVE record and NVD detail are available. The CVE record was published on 2026-07-20T07:16:35.190Z and has not been modified since then. Defenders should verify LearnPress WordPress plugin version and configuration. Limited source information may impact thorough vulnerability assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12970 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12970
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12970 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12970
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/d0a2780f-ab13-4bb8-935d-2aeba1de12d2/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.