Home/Product/thimpress learnpress
Product

thimpress learnpress

45 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-13128
< 4.2.7.5.1
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privil
4.8MEDIUM
CVE-2024-13127
< 4.2.7.5.1
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privil
4.8MEDIUM
CVE-2024-13599
< 4.2.7.5.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and
6.4MEDIUM
CVE-2024-9881
< 4.2.7.2
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privileg
4.8MEDIUM
CVE-2024-10010
< 4.2.7.2
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privileg
4.8MEDIUM
CVE-2024-11868
< 4.2.7.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
5.3MEDIUM
CVE-2024-8529
< 4.2.7.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-
10.0CRITICAL
CVE-2024-8522
< 4.2.7.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the
10.0CRITICAL
CVE-2024-39641
< 4.2.6.9
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.
4.3MEDIUM
CVE-2024-7548
< 4.2.6.9.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in
8.8HIGH
CVE-2024-6589
<= 4.2.6.8.2
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ
8.8HIGH
CVE-2024-6099
< 4.2.6.8.2
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to unauthenticated bypass to user registration in version
5.3MEDIUM
CVE-2024-6088
< 4.2.6.8.2
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to unauthorized user registration due to a missing capabi
5.3MEDIUM
CVE-2023-36516
< 4.2.3.1
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
7.6HIGH
CVE-2023-36515
< 4.2.3.1
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
7.3HIGH
CVE-2024-5483
< 4.2.6.8.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
5.3MEDIUM
CVE-2024-4971
< 4.2.6.7
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parame
6.4MEDIUM
CVE-2024-4444
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to bypass to user registration in versions up to, and inc
5.3MEDIUM
CVE-2024-4434
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ paramet
9.8CRITICAL
CVE-2024-4397
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
8.8HIGH
CVE-2024-4277
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_html’
6.4MEDIUM
CVE-2024-3560
< 4.2.6.5
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all v
6.4MEDIUM
CVE-2024-1463
< 4.2.6.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, an
4.4MEDIUM
CVE-2024-1289
< 4.2.6.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to
6.5MEDIUM
CVE-2024-2115
< 4.0.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
8.8HIGH
CVE-2023-5558
< 4.2.5.5
The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, lead
6.1MEDIUM
CVE-2023-6634
<= 4.2.5.7
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_c
8.1HIGH
CVE-2023-6567
< 4.2.5.8
The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up
9.8CRITICAL
CVE-2023-6223
<= 4.2.5.7
The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.
4.3MEDIUM
CVE-2023-30487
<= 4.0.2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThimPress LearnPress Export Import plugin <= 4.0.2 versions.
7.1HIGH
CVE-2022-47615
< 4.2.0
Local File Inclusion vulnerability in LearnPress - WordPress LMS Plugin <= 4.1.7.3.2 versions.
9.3CRITICAL
CVE-2022-45820
<= 4.1.7.3.2
SQL Injection (SQLi) vulnerability in LearnPress - WordPress LMS Plugin <= 4.1.7.3.2 versions.
9.1CRITICAL
CVE-2022-45808
<= 4.1.7.3.2
SQL Injection vulnerability in LearnPress - WordPress LMS Plugin <= 4.1.7.3.2 versions.
9.9CRITICAL
CVE-2022-3360
< 4.1.7.2
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users,
8.1HIGH
CVE-2022-0271
< 4.1.6
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the
6.1MEDIUM
CVE-2022-0377
< 4.1.5
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this
4.3MEDIUM
CVE-2021-24951
< 4.1.4
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statem
9.8CRITICAL
CVE-2021-39348
<= 4.1.3.1
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile p
5.5MEDIUM
CVE-2021-24702
< 4.1.3.1
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which c
4.8MEDIUM
CVE-2020-11511
< 3.2.6.9
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor
8.1HIGH
CVE-2020-6010
<= 3.2.6.7
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
8.8HIGH
CVE-2020-7916
<= 3.2.6.5
be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to ass
6.5MEDIUM
CVE-2018-16175
< 3.1.0
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrar
7.2HIGH
CVE-2018-16174
< 3.1.0
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites
6.1MEDIUM
CVE-2018-16173
< 3.1.0
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or
6.1MEDIUM
threatengine.sh