Medium severity5.4NVD Advisory· Published Apr 23, 2026· Updated May 10, 2026
CVE-2026-3007
CVE-2026-3007
Description
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Package: https://wordpress.org/themes/lms
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.