Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThimPress — Vulnerabilities & Security Advisories 120

Browse all 120 CVE security advisories affecting ThimPress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThimPress operates as a software vendor specializing in WordPress plugins and themes, primarily targeting small business owners and web developers seeking ready-made digital solutions. Security audits reveal a concerning pattern of vulnerabilities, with approximately 100 Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve Cross-Site Scripting (XSS), SQL Injection, and Remote Code Execution (RCE), often stemming from insufficient input validation and weak authentication mechanisms. Privilege escalation issues further compound the risk, allowing unauthorized users to manipulate site configurations or execute malicious scripts. The high volume of recorded CVEs suggests systemic gaps in the development lifecycle, particularly regarding code review and secure coding practices. While specific major data breaches linked directly to ThimPress products remain largely unpublicized, the persistent presence of critical vulnerabilities poses significant risks to dependent websites. This profile highlights the urgent need for rigorous security testing and timely patching to mitigate potential exploitation by attackers targeting the WordPress ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-12230 LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-79 6.4 Medium 2026-09-08
CVE-2026-82024 LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles — LearnPress CWE-79 5.4 Medium 2026-09-03
CVE-2026-82023 LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert — LearnPress CWE-863 4.3 Medium 2026-09-03
CVE-2026-77823 LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-89 4.9 Medium 2026-09-01
CVE-2026-75982 LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 4.4 Medium 2026-08-25
CVE-2026-66458 WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability — RealPress CWE-89 9.3 Critical 2026-08-13
CVE-2026-15464 WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute — WP Hotel Booking CWE-79 6.4 Medium 2026-07-24
CVE-2026-15094 WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter — WP Hotel Booking CWE-79 6.1 Medium 2026-07-17
CVE-2026-13765 LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 7.5 High 2026-07-17
CVE-2026-11901 WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler — WP Hotel Booking CWE-345 5.3 Medium 2026-07-11
CVE-2026-11392 WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters — WP Hotel Booking CWE-79 6.1 Medium 2026-07-10
CVE-2026-12732 LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-79 6.4 Medium 2026-07-01
CVE-2026-11988 LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-639 6.5 Medium 2026-07-01
CVE-2026-8502 LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 5.3 Medium 2026-06-06
CVE-2026-7565 LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter — LearnPress – Backup & Migration Tool CWE-22 4.9 Medium 2026-06-06
CVE-2026-7566 LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload — LearnPress – Backup & Migration Tool CWE-502 6.6 Medium 2026-06-06
CVE-2025-53346 WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control Vulnerability — Thim Core CWE-862 4.3 Medium 2026-06-02
CVE-2025-53345 WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerability — Thim Core CWE-862 8.8 High 2026-06-02
CVE-2026-48865 WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) vulnerability — LearnPress CWE-79 7.1 High 2026-06-01
CVE-2026-7648 LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-639 4.3 Medium 2026-05-14
CVE-2026-4650 FundPress <= 2.0.8 - Missing Authorization to Unauthenticated Arbitrary Donation Status Modification via donate_action_status AJAX Handler — FundPress – WordPress Donation Plugin CWE-862 5.3 Medium 2026-05-02
CVE-2026-4365 LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 9.1 Critical 2026-04-14
CVE-2026-4333 LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-79 6.4 Medium 2026-04-08
CVE-2026-25002 WordPress LearnPress – Sepay Payment plugin <= 4.0.0 - Broken Authentication vulnerability — LearnPress – Sepay Payment CWE-288 7.5 High 2026-03-25
CVE-2026-3225 LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 4.3 Medium 2026-03-23
CVE-2026-27065 WordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerability — BuilderPress CWE-98 9.8 Critical 2026-03-19
CVE-2026-1870 Thim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course Disclosure — Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor CWE-862 5.3 Medium 2026-03-14
CVE-2026-3226 LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 4.3 Medium 2026-03-12
CVE-2026-1787 LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Course Deletion — LearnPress – Backup & Migration Tool CWE-862 4.8 Medium 2026-02-21
CVE-2026-27050 WordPress RealPress plugin <= 1.1.0 - Cross Site Request Forgery (CSRF) vulnerability — RealPress CWE-352 5.4 Medium 2026-02-19

This page lists every published CVE security advisory associated with ThimPress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.