Thimpress
Thimpress Learnpress: vulnerabilities and CVEs
Thimpress Learnpress has 84 published vulnerabilities, 36 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.
CVEs84
Last 12 months36
Critical7
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93882 | High (7.5) | — | — | Oct 1, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the… |
| CVE-2026-86446 | Low (3.7) | 0.28% | — | Sep 17, 2026 | The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a… |
| CVE-2026-86449 | Medium (5.3) | 0.34% | — | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthenticated attackers to list courses that… |
| CVE-2026-86448 | Low (3.7) | 0.31% | — | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a previously generated order export file, allowing unauthenticated attackers who can determine… |
| CVE-2026-86447 | Medium (5.3) | 0.34% | — | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user… |
| CVE-2026-86445 | Medium (5.3) | 0.34% | — | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every… |
| CVE-2026-86444 | High (7.1) | 0.28% | — | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser… |
| CVE-2026-12230 | Medium (6.4) | 0.20% | — | Sep 8, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including,… |
| CVE-2026-82024 | Medium (5.1) | 0.24% | — | Sep 3, 2026 | LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting… |
| CVE-2026-82023 | Medium (5.3) | 0.29% | — | Sep 3, 2026 | LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other… |
| CVE-2026-77823 | Medium (4.9) | 0.44% | — | Sep 1, 2026 | The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient escaping on the… |
| CVE-2026-78125 | Medium (5.3) | 0.34% | — | Aug 27, 2026 | The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, 4.0.2, allowing unauthenticated attackers to disclose the payment… |
| CVE-2026-75982 | Medium (4.4) | 0.38% | — | Aug 25, 2026 | The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX action. The… |
| CVE-2026-12976 | Medium (6.5) | 0.37% | — | Aug 12, 2026 | The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson content, allowing any authenticated user such as a… |
| CVE-2026-12971 | Low (2.2) | 0.24% | — | Aug 10, 2026 | The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external… |
| CVE-2026-12970 | High (7.1) | 0.25% | — | Jul 20, 2026 | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in… |
| CVE-2026-13765 | High (7.5) | 0.68% | — | Jul 17, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes… |
| CVE-2026-12732 | Medium (6.4) | 0.33% | — | Jul 1, 2026 | The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization… |
| CVE-2026-11988 | Medium (6.5) | 0.47% | — | Jul 1, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter… |
| CVE-2026-8383 | Medium (5.3) | 0.69% | — | Jun 17, 2026 | The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles,… |
| CVE-2026-8502 | Medium (5.3) | 0.60% | — | Jun 6, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the 'return_type' parameter.… |
| CVE-2026-48865 | High (7.1) | 0.25% | — | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6. |
| CVE-2026-7648 | Medium (4.3) | 0.40% | — | May 14, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. This is due to… |
| CVE-2026-4365 | Critical (9.1) | 0.85% | — | Apr 14, 2026 | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin… |
| CVE-2026-4333 | Medium (6.4) | 0.35% | — | Apr 8, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_courses shortcode in all versions up to and including 4.3.3. This is… |
| CVE-2026-3225 | Medium (4.3) | 0.34% | — | Mar 23, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answers due to a missing capability check in the delete_question_answer() function of the… |
| CVE-2026-3226 | Medium (4.3) | 0.34% | — | Mar 12, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering due to missing capability checks on all 10 functions in the SendEmailAjax class in all versions up… |
| CVE-2025-14798 | Medium (5.3) | 0.28% | — | Jan 20, 2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for… |
| CVE-2025-14802 | Medium (5.4) | 0.33% | — | Jan 7, 2026 | The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a… |
| CVE-2025-13964 | Medium (5.3) | 0.26% | — | Jan 6, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2.… |