Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — Vulnerabilities & Security Advisories 42

All 42 CVE vulnerabilities found in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the LearnPress WordPress LMS Plugin, specifically identifying security weaknesses and their associated Common Vulnerability and Disclosure (CVD) classifications. The collection covers various vulnerability types found in this plugin over a defined historical period, providing a centralized repository for analyzing its security posture. Readers can use this index to track the vendor's security advisories, understand the specific weakness classes affecting online course creation and selling functions, and review the complete vulnerability history of the LearnPress product. The data highlights recurring patterns in plugin security, such as authentication bypasses or data exposure, enabling users to assess risks for their LMS environments without searching individual reports.

Vendor: thimpress

CVE ID Title CVSS Severity Published
CVE-2024-4971 LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CWE-79 6.4 Medium 2024-05-22
CVE-2024-4277 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter CWE-79 6.4 Medium 2024-05-10
CVE-2024-4444 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration CWE-420 5.3 Medium 2024-05-10
CVE-2024-4434 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection CWE-89 9.8 Critical 2024-05-10
CVE-2024-4397 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload CWE-434 8.8 High 2024-05-09
CVE-2024-3560 LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium 2024-04-19
CVE-2024-1463 LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2024-04-09
CVE-2024-1289 LearnPress <= 4.2.6.3 - Insecure Direct Object Reference CWE-285 6.5 Medium 2024-04-09
CVE-2024-2115 LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation CWE-352 8.8 High 2024-04-05
CVE-2023-6567 LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by CWE-89 9.8 Critical 2024-01-11
CVE-2023-6634 LearnPress <= 4.2.5.7 - Command Injection CWE-88 8.1 High 2024-01-11
CVE-2023-6223 LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure CWE-639 4.3 Medium 2024-01-11

All 42 known CVE vulnerabilities affecting LearnPress – WordPress LMS Plugin for Create and Sell Online Courses with full Chinese analysis, references, and POCs where available.