📦 Learnpress

by Thimpress

🔍 What is Learnpress?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-8522

CRITICAL CVSS 10.0 Sep 12, 2024

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites using the LearnPress plugin. Attackers can extract sensitive database information by manipulatin...

CVE-2024-4434

CRITICAL CVSS 9.8 May 14, 2024

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the LearnPress plugin. Attackers can extract sensitive database information lik...

CVE-2023-6567

CRITICAL CVSS 9.8 Jan 11, 2024

This vulnerability allows unauthenticated attackers to perform time-based SQL injection attacks on WordPress sites using the LearnPress plugin. Attackers can extract sensitive database information by ...

CVE-2023-36515

HIGH CVSS 7.3 Jun 19, 2024

CVE-2023-36515 is a missing authorization vulnerability in the LearnPress WordPress plugin that allows unauthenticated attackers to perform actions that should require authentication. This affects all...

CVE-2024-4397

HIGH CVSS 8.8 May 14, 2024

The LearnPress WordPress LMS plugin has a vulnerability that allows authenticated attackers with Instructor-level permissions or higher to upload arbitrary files due to missing file type validation. T...

CVE-2023-6634

HIGH CVSS 8.1 Jan 11, 2024

The LearnPress WordPress plugin contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP functions with one parameter. This can lead to remote code exe...

CVE-2023-30487

HIGH CVSS 7.1 May 18, 2023

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the ThimPress LearnPress Export Import WordPress plugin allows attackers to inject malicious scripts via crafted requests. This af...

CVE-2020-11511

HIGH CVSS 8.1 Jul 30, 2021

This vulnerability in the LearnPress WordPress plugin allows remote attackers to escalate any user's privileges to 'LP Instructor' role via the 'accept-to-be-teacher' action parameter. This affects Wo...

CVE-2024-13127

MEDIUM CVSS 4.8 May 15, 2025

This vulnerability in the LearnPress WordPress plugin allows administrators to inject malicious scripts into plugin settings, which then execute when other users view those settings. It affects WordPr...

CVE-2024-13599

MEDIUM CVSS 6.4 Jan 25, 2025

This stored XSS vulnerability in LearnPress WordPress plugin allows authenticated attackers with LP Instructor access or higher to inject malicious scripts into lesson names. When users view affected ...

CVE-2024-9881

MEDIUM CVSS 4.8 Dec 12, 2024

This vulnerability allows high-privilege WordPress users (like administrators) to inject malicious scripts into LearnPress plugin settings, which then execute when other users view those settings. It ...

CVE-2024-6099

MEDIUM CVSS 5.3 Jul 2, 2024

This vulnerability allows unauthenticated attackers to bypass user registration controls in the LearnPress WordPress LMS plugin. Attackers can register accounts with the default role even when registr...

CVE-2024-4444

MEDIUM CVSS 5.3 May 14, 2024

This vulnerability allows unauthenticated attackers to bypass user registration controls in LearnPress WordPress LMS Plugin, enabling them to create accounts with default roles even when registration ...