thimpress learnpress是thimpress公司开源的一套搭建学习管理系统的方案。 Thimpress learnpress 4.3.7之前版本存在安全漏洞,该漏洞源于REST端点未正确限制 环境,导致未经验证的访问者可通过特制请求检索每个返回用户的角色、完整权限映射、额外权限、语言环境和注册日期。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | LearnPress | < 4.3.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | LearnPress | 0 ~ 4.3.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LearnPress WordPress plugin < 4.3.7 contains an information disclosure vulnerability caused by missing capability checks on a REST endpoint, letting unauthenticated visitors retrieve sensitive user role and capability data via crafted requests. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-8383.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-9570 | Taskbuilder < 5.0.8 - Reflected XSS via Shortcode | |
| CVE-2026-7850 | WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute | |
| CVE-2026-8089 | weMail < 2.1.3 - Reflected Cross-Site Scripting |
No comments yet