WordPress LearnPress plugin before 4.1.6 contains a cross-site scripting vulnerability. It does not sanitize and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action.
id: CVE-2022-0271
info:
name: LearnPress <4.1.6 - Cross-Site Scripting
author: Akincibor
seve
...