| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-4444 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 5.3 | 2024-05-10 08:32:35 | Deep Dive |
| CVE-2024-4434 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Critical | 9.8 | 2024-05-10 08:32:33 | Deep Dive |
| CVE-2024-4397 | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | High | 8.8 | 2024-05-09 20:03:42 | Deep Dive |
| CVE-2024-3560 | LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.4 | 2024-04-19 01:57:09 | Deep Dive |
| CVE-2024-32588 | WordPress LearnPress Export Import plugin <= 4.0.3 - Reflected Cross Site Scripting (XSS) vulnerability | ThimPress | LearnPress Export Import | High | 7.1 | 2024-04-18 08:48:01 | Deep Dive |
| CVE-2024-1463 | LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 4.4 | 2024-04-09 18:59:12 | Deep Dive |
| CVE-2024-1289 | LearnPress <= 4.2.6.3 - Insecure Direct Object Reference | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 6.5 | 2024-04-09 18:58:32 | Deep Dive |
| CVE-2024-31241 | WordPress LearnPress Export Import plugin <= 4.0.3 - Auth. SQL Injection vulnerability | ThimPress | LearnPress Export Import | High | 7.6 | 2024-04-07 18:00:12 | Deep Dive |
| CVE-2024-2115 | LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | High | 8.8 | 2024-04-05 07:34:36 | Deep Dive |
| CVE-2023-5558 | LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting | Unknown | LearnPress | 中危 | - | 2024-01-16 15:54:33 | Deep Dive |
| CVE-2023-6567 | LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Critical | 9.8 | 2024-01-11 08:32:37 | Deep Dive |
| CVE-2023-6634 | LearnPress <= 4.2.5.7 - Command Injection | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | High | 8.1 | 2024-01-11 08:32:29 | Deep Dive |
| CVE-2023-6223 | LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Medium | 4.3 | 2024-01-11 06:49:32 | Deep Dive |
| CVE-2023-30487 | WordPress LearnPress Export Import Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS) | ThimPress | LearnPress Export Import | High | 7.1 | 2023-05-18 08:37:57 | Deep Dive |
| CVE-2022-45820 | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection | ThimPress | LearnPress – WordPress LMS Plugin | Critical | 9.1 | 2023-01-24 09:18:46 | Deep Dive |
| CVE-2022-45808 | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection | ThimPress | LearnPress – WordPress LMS Plugin | Critical | 9.9 | 2023-01-24 09:13:43 | Deep Dive |
| CVE-2022-47615 | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion | ThimPress | LearnPress – WordPress LMS Plugin | Critical | 9.3 | 2023-01-24 09:05:27 | Deep Dive |
| CVE-2022-3360 | LearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API | Unknown | LearnPress – WordPress LMS Plugin | 高危 | - | 2022-10-31 00:00:00 | Deep Dive |
| CVE-2022-0271 | LearnPress < 4.1.6 - Reflected Cross-Site Scripting | Unknown | LearnPress – WordPress LMS Plugin | 中危 | - | 2022-04-11 14:40:41 | Deep Dive |
| CVE-2022-0377 | LearnPress < 4.1.5 - Arbitrary Image Renaming | Unknown | LearnPress | 中危 | - | 2022-02-28 09:06:50 | Deep Dive |