| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-22739 | WordPress LearnPress plugin <= 4.2.7.5 - Broken Access Control vulnerability | ThimPress | LearnPress | Medium | 5.3 | 2025-03-27 21:46:01 | Deep Dive |
| CVE-2025-24740 | WordPress Learnpress plugin <= 4.2.7.1 - Open Redirection vulnerability | ThimPress | LearnPress | Medium | 4.7 | 2025-01-27 14:22:18 | Deep Dive |
| CVE-2024-13599 | LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.4 | 2025-01-25 07:24:16 | Deep Dive |
| CVE-2024-9881 | LearnPress < 4.2.7.2 - Admin+ Stored XSS | Unknown | LearnPress | 中危 | - | 2024-12-12 06:00:19 | Deep Dive |
| CVE-2024-10010 | LearnPress < 4.2.7.2 - Admin+ Stored XSS | Unknown | LearnPress | 中危 | - | 2024-12-12 06:00:09 | Deep Dive |
| CVE-2024-11868 | LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-12-10 12:25:00 | Deep Dive |
| CVE-2024-9609 | LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting | thimpress | LearnPress – Backup & Migration Tool | Medium | 6.1 | 2024-11-15 04:29:06 | Deep Dive |
| CVE-2024-8522 | LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Critical | 10.0 | 2024-09-12 08:30:47 | Deep Dive |
| CVE-2024-8529 | LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Critical | 10.0 | 2024-09-12 08:30:46 | Deep Dive |
| CVE-2024-39641 | WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability | ThimPress | LearnPress | Medium | 4.3 | 2024-08-26 20:56:36 | Deep Dive |
| CVE-2024-39642 | WordPress LearnPress plugin <= 4.2.6.8.2 - Insecure Direct Object References (IDOR) vulnerability | ThimPress | LearnPress | Medium | 6.5 | 2024-08-13 10:47:20 | Deep Dive |
| CVE-2024-7548 | LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | High | 8.8 | 2024-08-08 05:31:46 | Deep Dive |
| CVE-2024-6589 | LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | High | 8.8 | 2024-07-25 10:59:52 | Deep Dive |
| CVE-2024-6099 | LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-07-02 11:01:36 | Deep Dive |
| CVE-2024-6088 | LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-07-02 11:01:35 | Deep Dive |
| CVE-2023-36515 | WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability | ThimPress | LearnPress | High | 7.3 | 2024-06-19 14:20:09 | Deep Dive |
| CVE-2023-36516 | WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerability | ThimPress | LearnPress | High | 7.6 | 2024-06-19 14:18:34 | Deep Dive |
| CVE-2024-5483 | LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-06-05 02:34:31 | Deep Dive |
| CVE-2024-4971 | LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.4 | 2024-05-22 05:32:47 | Deep Dive |
| CVE-2024-4277 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.4 | 2024-05-10 09:32:09 | Deep Dive |