Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ThimPress — Vulnerabilities & Security Advisories 121

Browse all 121 CVE security advisories affecting ThimPress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ThimPress operates as a software vendor specializing in WordPress plugins and themes, primarily targeting small business owners and web developers seeking ready-made digital solutions. Security audits reveal a concerning pattern of vulnerabilities, with approximately 100 Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve Cross-Site Scripting (XSS), SQL Injection, and Remote Code Execution (RCE), often stemming from insufficient input validation and weak authentication mechanisms. Privilege escalation issues further compound the risk, allowing unauthorized users to manipulate site configurations or execute malicious scripts. The high volume of recorded CVEs suggests systemic gaps in the development lifecycle, particularly regarding code review and secure coding practices. While specific major data breaches linked directly to ThimPress products remain largely unpublicized, the persistent presence of critical vulnerabilities poses significant risks to dependent websites. This profile highlights the urgent need for rigorous security testing and timely patching to mitigate potential exploitation by attackers targeting the WordPress ecosystem.

CVE ID Title CVSS Severity Published
CVE-2025-48267 WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerability — WP Pipes CWE-22 8.6 High 2025-06-09
CVE-2025-48336 WordPress Course Builder < 3.6.6 - PHP Object Injection Vulnerability — Course Builder CWE-502 9.8 Critical 2025-05-29
CVE-2025-39460 WordPress Eduma theme <= 5.6.4 - Broken Access Control vulnerability — Eduma CWE-862 5.3 Medium 2025-05-19
CVE-2025-47664 WordPress WP Pipes <= 1.4.2 - Server Side Request Forgery (SSRF) Vulnerability — WP Pipes CWE-918 4.4 Medium 2025-05-07
CVE-2025-47448 WordPress WP Hotel Booking plugin <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability — WP Hotel Booking CWE-352 4.3 Medium 2025-05-07
CVE-2025-39470 WordPress Ivy School theme <= 1.6.0 - Local File Inclusion Vulnerability — Ivy School CWE-35 8.1 High 2025-04-18
CVE-2025-22739 WordPress LearnPress plugin <= 4.2.7.5 - Broken Access Control vulnerability — LearnPress CWE-862 5.3 Medium 2025-03-27
CVE-2025-24740 WordPress Learnpress plugin <= 4.2.7.1 - Open Redirection vulnerability — LearnPress CWE-601 4.7 Medium 2025-01-27
CVE-2025-24601 WordPress FundPress plugin <= 2.0.6 - PHP Object Injection vulnerability — FundPress CWE-502 9.8 Critical 2025-01-27
CVE-2024-13599 LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-79 6.4 Medium 2025-01-25
CVE-2025-24725 WordPress Thim Elementor Kit Plugin <= 1.2.8 - Broken Access Control vulnerability — Thim Elementor Kit CWE-862 4.3 Medium 2025-01-24
CVE-2024-13447 WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrieval — WP Hotel Booking CWE-862 4.3 Medium 2025-01-22
CVE-2024-12370 WP Hotel Booking <= 2.1.5 - Missing Authorization — WP Hotel Booking CWE-284 5.3 Medium 2025-01-17
CVE-2025-22312 WordPress Thim Elementor Kit plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerability — Thim Elementor Kit CWE-79 6.5 Medium 2025-01-07
CVE-2024-12283 WP Pipes <= 1.4.1 - Reflected Cross-Site Scripting via x1 Parameter — WP Pipes CWE-79 6.1 Medium 2024-12-11
CVE-2024-11868 LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-284 5.3 Medium 2024-12-10
CVE-2024-9609 LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting — LearnPress – Backup & Migration Tool CWE-79 6.1 Medium 2024-11-15
CVE-2024-51582 WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability — WP Hotel Booking CWE-35 7.5 High 2024-11-04
CVE-2024-7855 WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload — WP Hotel Booking CWE-434 8.8 High 2024-10-02
CVE-2024-8522 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-89 10.0 Critical 2024-09-12
CVE-2024-8529 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-89 10.0 Critical 2024-09-12
CVE-2024-7717 WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injection — WP Events Manager CWE-89 8.8 High 2024-08-31
CVE-2024-39641 WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability — LearnPress CWE-352 4.3 Medium 2024-08-26
CVE-2024-39642 WordPress LearnPress plugin <= 4.2.6.8.2 - Insecure Direct Object References (IDOR) vulnerability — LearnPress CWE-639 6.5 Medium 2024-08-13
CVE-2024-7548 LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-89 8.8 High 2024-08-08
CVE-2024-6589 LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-98 8.8 High 2024-07-25
CVE-2024-6099 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-420 5.3 Medium 2024-07-02
CVE-2024-6088 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses CWE-862 5.3 Medium 2024-07-02
CVE-2024-3605 WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection — WP Hotel Booking CWE-89 10.0 Critical 2024-06-20
CVE-2023-36515 WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability — LearnPress CWE-862 7.3 High 2024-06-19

This page lists every published CVE security advisory associated with ThimPress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.