{"id":"CVE-2026-86444","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86444","summary":"The LearnPress  WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute…","details":"The LearnPress  WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who opens a crafted link, including a logged in administrator. Only sites running a classic, non-block  are affected.","published":"2026-09-16T06:00:14.986Z","modified":"2026-09-17T12:35:13.339Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://wpscan.com/vulnerability/c11f39bd-7db8-495f-9118-48b63ee0858f/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T12:35:13.339Z"}}