All 4 CVE vulnerabilities found in LearnPress – Backup & Migration Tool, with AI-generated Chinese analysis, references, and POCs.
Vendor: thimpress
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-7566 | LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload CWE-502 | 6.6 | Medium | 2026-06-06 |
| CVE-2026-7565 | LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter CWE-22 | 4.9 | Medium | 2026-06-06 |
| CVE-2026-1787 | LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Course Deletion CWE-862 | 4.8 | Medium | 2026-02-21 |
| CVE-2024-9609 | LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting CWE-79 | 6.1 | Medium | 2024-11-15 |
All 4 known CVE vulnerabilities affecting LearnPress – Backup & Migration Tool with full Chinese analysis, references, and POCs where available.