Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.60% | — | Thimpress LearnpressAI | 6/6/2026 | 23/7/2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the 'return_type' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the… | |
| Aplazada | Media (4.9) | 0.97% | — | Learnpress Backup MigrationAI | 6/6/2026 | 23/7/2026 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read… | |
| Aplazada | Alta (7.1) | 0.25% | — | Thimpress LearnpressAI | 1/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6. | |
| Aplazada | Media (4.3) | 0.40% | — | Thimpress LearnpressAI | 14/5/2026 | 17/6/2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. This is due to improper handling of user-supplied request parameters in the REST API endpoint, which passes the… | |
| Aplazada | Crítica (9.1) | 0.85% | — | Thimpress LearnpressAI | 14/4/2026 | 17/6/2026 | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visitors, and uses that… | |
| Aplazada | Media (6.4) | 0.35% | — | Thimpress LearnpressAI | 8/4/2026 | 24/7/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_courses shortcode in all versions up to and including 4.3.3. This is due to insufficient input sanitization and output escaping on the 'skin' shortcode attribute. The… | |
| Aplazada | Alta (7.5) | 0.27% | — | Thimpress Learnpress Sepay PaymentAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress – Sepay Payment: from n/a through <= 4.0.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Thimpress LearnpressAI | 23/3/2026 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answers due to a missing capability check in the delete_question_answer() function of the EditQuestionAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_lp_ajax() dispatcher… | |
| Aplazada | Media (4.3) | 0.34% | — | Thimpress LearnpressAI | 12/3/2026 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering due to missing capability checks on all 10 functions in the SendEmailAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_lp_ajax() dispatcher verifies a wp_rest nonce but… | |
| Aplazada | Media (4.8) | 0.24% | — | Thimpress Learnpress Export ImportAI | 21/2/2026 | 17/6/2026 | The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to delete course… | |
| Aplazada | Media (6.5) | 0.15% | — | Thimpress Learnpress - Course ReviewAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress – Course Review learnpress-course-review allows Stored XSS.This issue affects LearnPress – Course Review: from n/a through <= 4.1.9. | |
| Aplazada | Media (5.3) | 0.28% | — | Thimpress LearnpressAI | 20/1/2026 | 17/6/2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and last names. Other… | |
| Aplazada | Media (5.4) | 0.32% | — | Thimpress LearnpressAI | 7/1/2026 | 30/9/2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a parameter mismatch between the DELETE operation and authorization check, where the endpoint uses… | |
| Aplazada | Media (5.3) | 0.27% | — | Thimpress LearnpressAI | 6/1/2026 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents by… | |
| Aplazada | Alta (7.5) | 0.27% | — | Thimpress LearnpressAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.9.4. | |
| Aplazada | Media (5.3) | 0.89% | — | Thimpress LearnpressAI | 16/12/2025 | 30/9/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total… | |
| Aplazada | Media (6.4) | 0.23% | — | Thimpress LearnpressAI | 15/12/2025 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary… | |
| Aplazada | Media (6.5) | 0.19% | — | Thimpress LearnpressAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress learnpress allows Stored XSS.This issue affects LearnPress: from n/a through <= 4.2.9.4. | |
| Aplazada | Media (5.3) | 0.98% | — | Thimpress LearnpressAI | 21/11/2025 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template… | |
| Aplazada | Alta (7.5) | 0.43% | — | Thimpress Learnpress Export ImportAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows PHP Local File Inclusion.This issue affects LearnPress Export Import: from n/a through <= 4.1.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Thimpress Learnpress Export ImportAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows Reflected XSS.This issue affects LearnPress Export Import: from n/a through <= 4.0.9. | |
| Aplazada | Media (6.5) | 0.46% | — | Thimpress LearnpressAI | 18/10/2025 | 17/6/2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permission_callback set to __return_true. This makes it possible for… | |
| Analizada | Media (4.8) | 0.34% | — | Thimpress Learnpress | 15/5/2025 | 17/6/2026 | The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.31% | — | Thimpress Learnpress | 15/5/2025 | 17/6/2026 | The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.3) | 0.28% | — | Thimpress LearnpressAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.7.5. |