VendorsThimPresslearnpressall versions
Vulnerabilities

ThimPress LearnPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2024-8522
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
Published 2024-09-12 · Modified
10.01 PoCEPSS 0.629
CVE-2024-8529
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
Published 2024-09-12 · Modified
10.0EPSS 0.118
CVE-2022-45808
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
Published 2023-01-24 · Modified
9.9EPSS 0.043
CVE-2023-6567
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
Published 2024-01-11 · Modified
9.8EPSS 0.514
CVE-2024-4434
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
Published 2024-05-10 · Modified
9.8EPSS 0.369
CVE-2023-6634
LearnPress <= 4.2.5.7 - Command Injection
Published 2024-01-11 · Modified
9.8EPSS 0.085
CVE-2022-47615
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
Published 2023-01-24 · Modified
9.8EPSS 0.051
CVE-2021-24951
LearnPress < 4.1.4 - Admin+ SQL Injection
Published 2021-12-13 · Modified
9.8EPSS 0.016
CVE-2023-36515
WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability
Published 2024-06-19 · Modified
9.8EPSS 0.004
CVE-2022-45820
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
Published 2023-01-24 · Modified
9.1EPSS 0.010
CVE-2020-6010
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
Published 2020-04-30 · Modified
8.81 PoCEPSS 0.492
CVE-2024-4397
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload
Published 2024-05-09 · Modified
8.8EPSS 0.010
CVE-2024-6589
LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion
Published 2024-07-25 · Modified
8.8EPSS 0.008
CVE-2024-7548
LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter
Published 2024-08-08 · Analyzed
8.8EPSS 0.006
CVE-2023-36516
WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerability
Published 2024-06-19 · Modified
8.8EPSS 0.005
CVE-2024-2115
LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation
Published 2024-04-05 · Modified
8.8EPSS 0.003
CVE-2024-39641
WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability
Published 2024-08-26 · Analyzed
8.8EPSS 0.002
CVE-2020-11511
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
Published 2021-07-27 · Modified
8.1EPSS 0.032
CVE-2022-3360
LearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API
Published 2022-10-31 · Modified
8.1EPSS 0.020
CVE-2018-16175
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
Published 2019-01-09 · Modified
7.2EPSS 0.013
CVE-2023-30487
WordPress LearnPress Export Import Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)
Published 2023-05-18 · Modified
7.1EPSS 0.004
CVE-2020-7916
be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role to an instructor/teacher and gain access to otherwise restricted data.
Published 2020-03-16 · Modified
6.5EPSS 0.011
CVE-2024-4444
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration
Published 2024-05-10 · Modified
6.5EPSS 0.007
CVE-2024-1289
LearnPress <= 4.2.6.3 - Insecure Direct Object Reference
Published 2024-04-09 · Modified
6.5EPSS 0.004
CVE-2024-4277
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter
Published 2024-05-10 · Modified
6.4EPSS 0.003
CVE-2024-3560
LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-04-19 · Modified
6.4EPSS 0.003
CVE-2024-13599
LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name
Published 2025-01-25 · Analyzed
6.4EPSS 0.003
CVE-2024-4971
LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Published 2024-05-22 · Modified
6.4EPSS 0.003
CVE-2022-0271
LearnPress < 4.1.6 - Reflected Cross-Site Scripting
Published 2022-04-11 · Modified
6.1EPSS 0.019
CVE-2018-16174
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2019-01-09 · Modified
6.1EPSS 0.010
CVE-2018-16173
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2019-01-09 · Modified
6.1EPSS 0.010
CVE-2023-5558
LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
Published 2024-01-16 · Modified
6.1EPSS 0.009
CVE-2021-39348
LearnPress – WordPress LMS Plugin <= 4.1.3.1 Authenticated Stored Cross-Site Scripting
Published 2021-10-21 · Modified
5.5EPSS 0.052
CVE-2024-11868
LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API
Published 2024-12-10 · Modified
5.3EPSS 0.012
CVE-2024-5483
LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
Published 2024-06-05 · Modified
5.3EPSS 0.010
CVE-2024-6088
LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass
Published 2024-07-02 · Modified
5.3EPSS 0.006
CVE-2024-6099
LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2021-24702
LearnPress < 4.1.3.1 - Multiple Admin+ Stored Cross-Site Scripting
Published 2021-10-18 · Modified
4.8EPSS 0.007
CVE-2024-10010
LearnPress < 4.2.7.2 - Admin+ Stored XSS
Published 2024-12-12 · Analyzed
4.8EPSS 0.005
CVE-2024-1463
LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting
Published 2024-04-09 · Modified
4.8EPSS 0.004
1 / 2Next →