Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThimPress — Vulnerabilities & Security Advisories 120

Browse all 120 CVE security advisories affecting ThimPress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThimPress operates as a software vendor specializing in WordPress plugins and themes, primarily targeting small business owners and web developers seeking ready-made digital solutions. Security audits reveal a concerning pattern of vulnerabilities, with approximately 100 Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve Cross-Site Scripting (XSS), SQL Injection, and Remote Code Execution (RCE), often stemming from insufficient input validation and weak authentication mechanisms. Privilege escalation issues further compound the risk, allowing unauthorized users to manipulate site configurations or execute malicious scripts. The high volume of recorded CVEs suggests systemic gaps in the development lifecycle, particularly regarding code review and secure coding practices. While specific major data breaches linked directly to ThimPress products remain largely unpublicized, the persistent presence of critical vulnerabilities poses significant risks to dependent websites. This profile highlights the urgent need for rigorous security testing and timely patching to mitigate potential exploitation by attackers targeting the WordPress ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-24361 WordPress LearnPress – Course Review plugin <= 4.1.9 - Cross Site Scripting (XSS) vulnerability — LearnPress – Course Review CWE-79 6.5 Medium 2026-01-22
CVE-2025-14798 LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 5.3 Medium 2026-01-20
CVE-2025-13725 Gutenberg Thim Blocks <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameter — Thim Blocks CWE-22 6.5 Medium 2026-01-17
CVE-2025-14075 WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter — WP Hotel Booking CWE-200 5.3 Medium 2026-01-17
CVE-2025-14802 LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-639 5.4 Medium 2026-01-07
CVE-2025-13964 LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 5.3 Medium 2026-01-06
CVE-2025-53344 WordPress Thim Core Plugin <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability — Thim Core CWE-352 4.3 Medium 2026-01-05
CVE-2025-66054 WordPress LearnPress plugin <= 4.2.9.4 - Broken Access Control vulnerability — LearnPress CWE-862 7.5 High 2025-12-18
CVE-2025-13956 LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 5.3 Medium 2025-12-16
CVE-2025-14387 LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-79 6.4 Medium 2025-12-15
CVE-2025-63013 WordPress WP Hotel Booking plugin <= 2.2.7 - Sensitive Data Exposure vulnerability — WP Hotel Booking CWE-497 4.3 Medium 2025-12-09
CVE-2025-63011 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability — WP Hotel Booking CWE-79 5.9 Medium 2025-12-09
CVE-2025-63012 WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Request Forgery (CSRF) vulnerability — WP Hotel Booking CWE-352 4.3 Medium 2025-12-09
CVE-2025-67594 WordPress Thim Elementor Kit plugin <= 1.3.3 - Insecure Direct Object References (IDOR) vulnerability — Thim Elementor Kit CWE-639 4.3 Medium 2025-12-09
CVE-2025-67573 WordPress Sailing theme < 4.4.6 - Broken Access Control vulnerability — Sailing CWE-862 5.3 Medium 2025-12-09
CVE-2025-67536 WordPress LearnPress plugin <= 4.2.9.4 - Cross Site Scripting (XSS) vulnerability — LearnPress CWE-79 6.5 Medium 2025-12-09
CVE-2025-67526 WordPress Sailing theme < 4.4.6 - Local File Inclusion vulnerability — Sailing CWE-98 7.5 High 2025-12-09
CVE-2025-11368 LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-200 5.3 Medium 2025-11-21
CVE-2025-60200 WordPress LearnPress Export Import plugin <= 4.1.2 - Local File Inclusion vulnerability — LearnPress Export Import CWE-98 7.5 High 2025-11-06
CVE-2025-54721 WordPress Resca theme <= 3.0.2 - Cross Site Scripting (XSS) vulnerability — Resca CWE-79 7.1 High 2025-11-06
CVE-2025-64195 WordPress Eduma theme <= 5.7.6 - Local File Inclusion vulnerability — Eduma CWE-98 7.5 High 2025-10-29
CVE-2025-64194 WordPress Eduma theme <= 5.7.6 - Cross Site Scripting (XSS) vulnerability — Eduma CWE-79 6.5 Medium 2025-10-29
CVE-2025-60227 WordPress WP Pipes plugin <= 1.4.3 - Arbitrary File Deletion vulnerability — WP Pipes CWE-22 8.6 High 2025-10-22
CVE-2025-49992 WordPress LearnPress Export Import plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerability — LearnPress Export Import CWE-79 7.1 High 2025-10-22
CVE-2025-11372 LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 6.5 Medium 2025-10-18
CVE-2025-57987 WordPress WP Events Manager Plugin <= 2.2.1 - Broken Access Control Vulnerability — WP Events Manager CWE-862 5.3 Medium 2025-09-22
CVE-2025-28977 WordPress WP Pipes Plugin <= 1.4.3 - Cross Site Scripting (XSS) Vulnerability — WP Pipes CWE-79 7.1 High 2025-08-20
CVE-2025-28979 WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerability — WP Pipes CWE-98 8.1 High 2025-08-14
CVE-2025-28982 WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerability — WP Pipes CWE-89 9.3 Critical 2025-07-16
CVE-2025-48267 WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerability — WP Pipes CWE-22 8.6 High 2025-06-09

This page lists every published CVE security advisory associated with ThimPress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.