Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregations for LearnPress, a widely used WordPress LMS plugin developed by Themeum, focusing on common weakness classes such as cross-site scripting and SQL injection. It compiles security issues reported for this specific product within the context of the broader WordPress ecosystem, covering data from its initial release through recent updates to ensure comprehensive historical tracking. Users can utilize this resource to track vendor advisories related to theme and plugin security, understand the technical implications of specific weakness classes within an LMS environment, and look up the product's complete vulnerability history to assess long-term security posture. By centralizing information on authorization bypasses, file inclusion flaws, and improper input validation, this aggregation serves as a neutral reference for security researchers, WordPress developers, and site administrators seeking to evaluate risks associated with this popular course creation tool. The collected data reflects publicly disclosed incidents and official patches, providing insight into how frequently this software has been targeted and how effectively the maintainers have addressed reported security gaps. This objective summary aids in understanding the attack surface of LearnPress without implying any endorsement or condemnation of the vendor, allowing users to make informed decisions about their own implementation and update strategies. The focus remains strictly on factual security data to support informed risk management practices.

Vendor: thimpress

CVE IDTitleCVSSSeverityPublished
CVE-2026-13765 LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints CWE-862 7.5 High2026-07-17
CVE-2026-12732 LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute CWE-79 6.4 Medium2026-07-01
CVE-2026-11988 LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter CWE-639 6.5 Medium2026-07-01
CVE-2026-8502 LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters CWE-862 5.3 Medium2026-06-06
CVE-2026-7648 LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter CWE-639 4.3 Medium2026-05-14
CVE-2026-4365 LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion CWE-862 9.1 Critical2026-04-14
CVE-2026-4333 LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute CWE-79 6.4 Medium2026-04-08
CVE-2026-3225 LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion CWE-862 4.3 Medium2026-03-23
CVE-2026-3226 LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering CWE-862 4.3 Medium2026-03-12
CVE-2025-14798 LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API CWE-862 5.3 Medium2026-01-20
CVE-2025-14802 LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion CWE-639 5.4 Medium2026-01-07
CVE-2025-13964 LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification CWE-862 5.3 Medium2026-01-06
CVE-2025-13956 LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure CWE-862 5.3 Medium2025-12-16
CVE-2025-14387 LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social CWE-79 6.4 Medium2025-12-15
CVE-2025-11368 LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure CWE-200 5.3 Medium2025-11-21
CVE-2025-11372 LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation CWE-862 6.5 Medium2025-10-18
CVE-2024-13599 LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name CWE-79 6.4 Medium2025-01-25
CVE-2024-11868 LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API CWE-284 5.3 Medium2024-12-10
CVE-2024-8522 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' CWE-89 10.0 Critical2024-09-12
CVE-2024-8529 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' CWE-89 10.0 Critical2024-09-12
CVE-2024-7548 LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter CWE-89 8.8 High2024-08-08
CVE-2024-6589 LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion CWE-98 8.8 High2024-07-25
CVE-2024-6099 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration CWE-420 5.3 Medium2024-07-02
CVE-2024-6088 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass CWE-862 5.3 Medium2024-07-02
CVE-2024-5483 LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API CWE-200 5.3 Medium2024-06-05
CVE-2024-4971 LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CWE-79 6.4 Medium2024-05-22
CVE-2024-4277 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter CWE-79 6.4 Medium2024-05-10
CVE-2024-4444 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration CWE-420 5.3 Medium2024-05-10
CVE-2024-4434 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection CWE-89 9.8 Critical2024-05-10
CVE-2024-4397 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload CWE-434 8.8 High2024-05-09

All 37 known CVE vulnerabilities affecting LearnPress – WordPress LMS Plugin for Create and Sell Online Courses with full Chinese analysis, references, and POCs where available.