Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities associated with the LearnPress WordPress LMS Plugin, a popular tool for creating and selling online courses, focusing on common weakness categories such as Cross-Site Scripting and Insecure Direct Object References. It aggregates reports from various tracking sources to provide a comprehensive overview of security issues identified in this specific software ecosystem over the past several years. By reviewing this compiled data, users can effectively track vendor advisories to stay informed about critical patches, understand the historical context of specific weakness classes within this widely used educational platform, and look up a product’s vulnerability history to assess its security posture over time. The information is organized to help administrators, developers, and security researchers quickly identify potential risks, understand the nature of each flaw, and determine the appropriate remediation steps. This resource serves as a centralized reference point for anyone seeking to audit the security status of their LearnPress installation or compare it against known industry standards. The page does not guarantee completeness, as new vulnerabilities may emerge or be reported through different channels at any time. Regular updates are intended to reflect the most current understanding of the threat landscape for this specific WordPress plugin, ensuring that stakeholders have access to timely and relevant security intelligence for maintaining a safe and reliable online learning environment.

Vendor: thimpress

CVE IDTitleCVSSSeverityPublished
CVE-2026-13765 LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints CWE-862 7.5 High2026-07-17
CVE-2026-12732 LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute CWE-79 6.4 Medium2026-07-01
CVE-2026-11988 LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter CWE-639 6.5 Medium2026-07-01
CVE-2026-8502 LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters CWE-862 5.3 Medium2026-06-06
CVE-2026-7648 LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter CWE-639 4.3 Medium2026-05-14
CVE-2026-4365 LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion CWE-862 9.1 Critical2026-04-14
CVE-2026-4333 LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute CWE-79 6.4 Medium2026-04-08
CVE-2026-3225 LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion CWE-862 4.3 Medium2026-03-23
CVE-2026-3226 LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering CWE-862 4.3 Medium2026-03-12
CVE-2025-14798 LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API CWE-862 5.3 Medium2026-01-20
CVE-2025-14802 LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion CWE-639 5.4 Medium2026-01-07
CVE-2025-13964 LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification CWE-862 5.3 Medium2026-01-06
CVE-2025-13956 LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure CWE-862 5.3 Medium2025-12-16
CVE-2025-14387 LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social CWE-79 6.4 Medium2025-12-15
CVE-2025-11368 LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure CWE-200 5.3 Medium2025-11-21
CVE-2025-11372 LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation CWE-862 6.5 Medium2025-10-18
CVE-2024-13599 LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name CWE-79 6.4 Medium2025-01-25
CVE-2024-11868 LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API CWE-284 5.3 Medium2024-12-10
CVE-2024-8522 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' CWE-89 10.0 Critical2024-09-12
CVE-2024-8529 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' CWE-89 10.0 Critical2024-09-12
CVE-2024-7548 LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter CWE-89 8.8 High2024-08-08
CVE-2024-6589 LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion CWE-98 8.8 High2024-07-25
CVE-2024-6099 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration CWE-420 5.3 Medium2024-07-02
CVE-2024-6088 LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass CWE-862 5.3 Medium2024-07-02
CVE-2024-5483 LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API CWE-200 5.3 Medium2024-06-05
CVE-2024-4971 LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter CWE-79 6.4 Medium2024-05-22
CVE-2024-4277 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter CWE-79 6.4 Medium2024-05-10
CVE-2024-4444 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration CWE-420 5.3 Medium2024-05-10
CVE-2024-4434 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection CWE-89 9.8 Critical2024-05-10
CVE-2024-4397 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload CWE-434 8.8 High2024-05-09

All 37 known CVE vulnerabilities affecting LearnPress – WordPress LMS Plugin for Create and Sell Online Courses with full Chinese analysis, references, and POCs where available.