CyberRota Analysis
AI-GeneratedThe LearnPress WordPress Plugin prior to version 4.4.6 is vulnerable to a stored cross-site scripting (XSS) attack, allowing authenticated users with the Instructor role to inject malicious JavaScript into quiz question answer titles. This vulnerability can lead to the execution of arbitrary scripts in the browsers of any user viewing the affected content, posing a risk to students, other instructors, and administrators. WordPress site administrators using this plugin should prioritize updating to mitigate potential exploitation.
Original NVD Description
LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.