Product
thimpress learnpress
45 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-13128
CVE-2024-13127
CVE-2024-13599
CVE-2024-9881
CVE-2024-10010
CVE-2024-11868
CVE-2024-8529
CVE-2024-8522
CVE-2024-39641
CVE-2024-7548
CVE-2024-6589
CVE-2024-6099
CVE-2024-6088
CVE-2023-36516
CVE-2023-36515
CVE-2024-5483
CVE-2024-4971
CVE-2024-4444
CVE-2024-4434
CVE-2024-4397
CVE-2024-4277
CVE-2024-3560
CVE-2024-1463
CVE-2024-1289
CVE-2024-2115
CVE-2023-5558
CVE-2023-6634
CVE-2023-6567
CVE-2023-6223
CVE-2023-30487
CVE-2022-47615
CVE-2022-45820
CVE-2022-45808
CVE-2022-3360
CVE-2022-0271
CVE-2022-0377
CVE-2021-24951
CVE-2021-39348
CVE-2021-24702
CVE-2020-11511
CVE-2020-6010
CVE-2020-7916
CVE-2018-16175
CVE-2018-16174
CVE-2018-16173
< 4.2.7.5.1
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privil
< 4.2.7.5.1
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privil
< 4.2.7.5.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and
< 4.2.7.2
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privileg
< 4.2.7.2
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privileg
< 4.2.7.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
< 4.2.7.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-
< 4.2.7.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the
< 4.2.6.9
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.
< 4.2.6.9.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in
<= 4.2.6.8.2
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ
< 4.2.6.8.2
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to unauthenticated bypass to user registration in version
< 4.2.6.8.2
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to unauthorized user registration due to a missing capabi
< 4.2.3.1
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
< 4.2.3.1
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
< 4.2.6.8.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
< 4.2.6.7
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parame
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to bypass to user registration in versions up to, and inc
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ paramet
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
< 4.2.6.6
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_html’
< 4.2.6.5
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all v
< 4.2.6.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, an
< 4.2.6.4
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to
< 4.0.1
The LearnPress - WordPress LMS Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
< 4.2.5.5
The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, lead
<= 4.2.5.7
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_c
< 4.2.5.8
The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up
<= 4.2.5.7
The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.
<= 4.0.2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThimPress LearnPress Export Import plugin <= 4.0.2 versions.
< 4.2.0
Local File Inclusion vulnerability in LearnPress - WordPress LMS Plugin <= 4.1.7.3.2 versions.
<= 4.1.7.3.2
SQL Injection (SQLi) vulnerability in LearnPress - WordPress LMS Plugin <= 4.1.7.3.2 versions.
<= 4.1.7.3.2
SQL Injection vulnerability in LearnPress - WordPress LMS Plugin <= 4.1.7.3.2 versions.
< 4.1.7.2
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users,
< 4.1.6
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the
< 4.1.5
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this
< 4.1.4
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statem
<= 4.1.3.1
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile p
< 4.1.3.1
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which c
< 3.2.6.9
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor
<= 3.2.6.7
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
<= 3.2.6.5
be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to ass
< 3.1.0
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrar
< 3.1.0
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites
< 3.1.0
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or