plugin

Learnpress Vulnerabilities

147 known security issues reported for the Learnpress WordPress plugin. Most recent disclosed Aug 24, 2026.

9 critical 14 high 55 medium

Running Learnpress on your site? Check whether your installed version is affected.

Scan your site free

LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter

medium

The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX action. The LP_Admin_Ajax::create_page() handler only checks the edit_pages capability and a wp_rest nonce (both available to Editors)...

CVSS:
4.4
Affected:
up to 4.4.4
Fixed in:
4.4.5
Disclosed:
Aug 24, 2026

CVE-2026-75982 on NVD →

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses < 4.4.4 - Authenticated (Subscriber+) Information Exposure

medium

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 4.4.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 4.4.4
Fixed in:
4.4.4
Disclosed:
Aug 13, 2026

CVE-2026-12976 on NVD →

LearnPress <= 4.4.3 - Authenticated (Instructor+) Server-Side Request Forgery

medium

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.4.3. This makes it possible for authenticated attackers, with Instructor-level access and above, to make web requests to arbitrary locations...

CVSS:
6.4
Affected:
up to 4.4.3
Fixed in:
4.4.4
Disclosed:
Aug 6, 2026

CVE-2026-12971 on NVD →

LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

high

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, e...

CVSS:
7.5
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Jul 16, 2026

CVE-2026-13765 on NVD →

LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute

medium

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization and output escaping in the FilterCourseTemplate::sections() method at line 98, where the attacker-cont...

CVSS:
6.4
Affected:
up to 4.4.0
Fixed in:
4.4.1
Disclosed:
Jun 30, 2026

CVE-2026-12732 on NVD →

LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter

medium

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers,...

CVSS:
6.5
Affected:
up to 4.3.9.1
Fixed in:
4.4.0
Disclosed:
Jun 30, 2026

CVE-2026-11988 on NVD →

LearnPress <= 4.4.0 - Reflected Cross-Site Scripting

medium

The LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 4.4.0
Fixed in:
4.4.1
Disclosed:
Jun 29, 2026

CVE-2026-12970 on NVD →

LearnPress <= 4.3.6 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure

medium

The LearnPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 4.3.6. This is due to missing validation of the context parameter in the get_items() function of the REST users controller, allowing unauthenticated requests to retrieve sensitive user fields. This makes it possib...

CVSS:
5.3
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Jun 27, 2026

CVE-2026-8383 on NVD →

LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters

medium

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the 'return_type' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the plaintex...

CVSS:
5.3
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Jun 5, 2026

CVE-2026-8502 on NVD →

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 - Reflected Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Jun 1, 2026

CVE-2026-48865 on NVD →

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter

medium

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. This is due to improper handling of user-supplied request parameters in the REST API endpoint, which passes the unsanitiz...

CVSS:
4.3
Affected:
up to 4.3.5
Fixed in:
4.3.6
Disclosed:
May 13, 2026

CVE-2026-7648 on NVD →

LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion

critical

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to unauthenticated visitors, and uses that n...

CVSS:
9.1
Affected:
up to 4.3.2.8
Fixed in:
4.3.3
Disclosed:
Apr 13, 2026

CVE-2026-4365 on NVD →

LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_courses shortcode in all versions up to and including 4.3.3. This is due to insufficient input sanitization and output escaping on the 'skin' shortcode attribute. The attri...

CVSS:
6.4
Affected:
up to 4.3.3
Fixed in:
4.3.4
Disclosed:
Apr 7, 2026

CVE-2026-4333 on NVD →

LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answers due to a missing capability check in the delete_question_answer() function of the EditQuestionAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_lp_ajax() dispatcher...

CVSS:
4.3
Affected:
up to 4.3.2.8
Fixed in:
4.3.3
Disclosed:
Mar 23, 2026

CVE-2026-3225 on NVD →

LearnPress - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering vulnerability

medium

Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering vulnerability

CVSS:
4.3
Affected:
up to 4.3.2.8
Fixed in:
4.3.3
Disclosed:
Mar 12, 2026

LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized email notification triggering due to missing capability checks on all 10 functions in the SendEmailAjax class in all versions up to, and including, 4.3.2.8. The AbstractAjax::catch_lp_ajax() dispatcher verifies a wp_rest nonce but...

CVSS:
4.3
Affected:
up to 4.3.2.8
Fixed in:
4.3.3
Disclosed:
Mar 11, 2026

CVE-2026-3226 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.3.2.5

unknown

[en] The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and last names. Other...

Affected:
up to 4.3.2.5
Fixed in:
4.3.2.5
Disclosed:
Jan 20, 2026

CVE-2025-14798 on NVD →

LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API

medium

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.3.2.4 via the get_item_permissions_check function. This makes it possible for unauthenticated attackers to extract sensitive data including user first names and last names. Other infor...

CVSS:
5.3
Affected:
up to 4.3.2.4
Fixed in:
4.3.2.5
Disclosed:
Jan 19, 2026

CVE-2025-14798 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.3.2.2

unknown

[en] The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a parameter mismatch between the DELETE operation and authorization check, where the endpoint uses fi...

Affected:
up to 4.3.2.2
Fixed in:
4.3.2.2
Disclosed:
Jan 7, 2026

CVE-2025-14802 on NVD →

LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion

medium

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp-json/lp/v1/material/{file_id} REST API endpoint. This is due to a parameter mismatch between the DELETE operation and authorization check, where the endpoint uses file_id...

CVSS:
5.4
Affected:
up to 4.3.2.1
Fixed in:
4.3.2.2
Disclosed:
Jan 6, 2026

CVE-2025-14802 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.3.2.1

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents by adding/removin...

Affected:
up to 4.3.2.1
Fixed in:
4.3.2.1
Disclosed:
Jan 6, 2026

CVE-2025-13964 on NVD →

LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents by adding/removing/upd...

CVSS:
5.3
Affected:
up to 4.3.2
Fixed in:
4.3.2.1
Disclosed:
Jan 5, 2026

CVE-2025-13964 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] <= 4.2.9.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.9.4.

Affected:
up to 4.2.9.4
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-66054 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.3.2

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including tot...

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Dec 16, 2025

CVE-2025-13956 on NVD →

LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statistics, including total re...

CVSS:
5.3
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Dec 15, 2025

CVE-2025-13956 on NVD →

LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Dec 15, 2025

CVE-2025-14387 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.3.2

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbit...

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Dec 15, 2025

CVE-2025-14387 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] <= 4.2.9.4 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress learnpress allows Stored XSS.This issue affects LearnPress: from n/a through <= 4.2.9.4.

Affected:
up to 4.2.9.4
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67536 on NVD →

LearnPress <= 4.2.9.4 - Missing Authorization

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.9.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.2.9.4
Fixed in:
4.3.0
Disclosed:
Nov 30, 2025

CVE-2025-66054 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.3.0

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only temp...

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Nov 21, 2025

CVE-2025-11368 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template...

CVSS:
5.3
Affected:
up to 4.2.9.4
Fixed in:
4.3.0
Disclosed:
Nov 20, 2025

CVE-2025-11368 on NVD →

LearnPress <= 4.2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...

CVSS:
6.4
Affected:
up to 4.2.9.4
Fixed in:
4.3.0
Disclosed:
Nov 6, 2025

CVE-2025-67536 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.9.4

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permission_callback set to __return_true. This makes it possible for u...

Affected:
up to 4.2.9.4
Fixed in:
4.2.9.4
Disclosed:
Oct 18, 2025

CVE-2025-11372 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permission_callback set to __return_true. This makes it possible for unauth...

CVSS:
6.5
Affected:
up to 4.2.9.3
Fixed in:
4.2.9.4
Disclosed:
Oct 17, 2025

CVE-2025-11372 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.5.1

unknown

[en] The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.2.7.5.1
Fixed in:
4.2.7.5.1
Disclosed:
May 15, 2025

CVE-2024-13127 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.5.1

unknown

[en] The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.2.7.5.1
Fixed in:
4.2.7.5.1
Disclosed:
May 15, 2025

CVE-2024-13128 on NVD →

LearnPress <= 4.2.7.5 - Missing Authorization

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.7.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.2.7.5
Fixed in:
4.2.7.6
Disclosed:
Mar 27, 2025

CVE-2025-22739 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.6

unknown

[en] Missing Authorization vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.2.7.5.

Affected:
up to 4.2.7.6
Fixed in:
4.2.7.6
Disclosed:
Mar 27, 2025

CVE-2025-22739 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an...

CVSS:
4.4
Affected:
up to 4.2.7.5
Fixed in:
4.2.7.5.1
Disclosed:
Jan 29, 2025

CVE-2024-13127 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an...

CVSS:
4.4
Affected:
up to 4.2.7.5
Fixed in:
4.2.7.5.1
Disclosed:
Jan 29, 2025

CVE-2024-13128 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.2

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ThimPress LearnPress. This issue affects LearnPress: from n/a through 4.2.7.1.

Affected:
up to 4.2.7.2
Fixed in:
4.2.7.2
Disclosed:
Jan 27, 2025

CVE-2025-24740 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.5.1

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping of a lesson name. This makes it possible for authenticated attackers, with LP Instructor-level access and...

Affected:
up to 4.2.7.5.1
Fixed in:
4.2.7.5.1
Disclosed:
Jan 25, 2025

CVE-2024-13599 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping of a lesson name. This makes it possible for authenticated attackers, with LP Instructor-level access and above...

CVSS:
6.4
Affected:
up to 4.2.7.5
Fixed in:
4.2.7.5.1
Disclosed:
Jan 24, 2025

CVE-2024-13599 on NVD →

LearnPress <= 4.2.7.1 - Authenticated (Subscriber+) Open Redirect

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.2.7.1. This is due to insufficient validation on a redirect url supplied. This makes it possible for authenticated attackers, with subscriber-level access and above, to redirect users to pot...

CVSS:
5.4
Affected:
up to 4.2.7.1
Fixed in:
4.2.7.2
Disclosed:
Jan 24, 2025

CVE-2025-24740 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.2

unknown

[en] The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.2.7.2
Fixed in:
4.2.7.2
Disclosed:
Dec 12, 2024

CVE-2024-9881 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.2

unknown

[en] The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.2.7.2
Fixed in:
4.2.7.2
Disclosed:
Dec 12, 2024

CVE-2024-10010 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.4

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course material.

Affected:
up to 4.2.7.4
Fixed in:
4.2.7.4
Disclosed:
Dec 10, 2024

CVE-2024-11868 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course material.

CVSS:
5.3
Affected:
up to 4.2.7.3
Fixed in:
4.2.7.4
Disclosed:
Dec 9, 2024

CVE-2024-11868 on NVD →

LearnPress <= 4.2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an...

CVSS:
4.4
Affected:
up to 4.2.7.1
Fixed in:
4.2.7.2
Disclosed:
Nov 21, 2024

CVE-2024-10010 on NVD →

LearnPress <= 4.2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions an...

CVSS:
4.4
Affected:
up to 4.2.7.1
Fixed in:
4.2.7.2
Disclosed:
Nov 21, 2024

CVE-2024-9881 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.1

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat...

Affected:
up to 4.2.7.1
Fixed in:
4.2.7.1
Disclosed:
Sep 12, 2024

CVE-2024-8522 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.7.1

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient prepar...

Affected:
up to 4.2.7.1
Fixed in:
4.2.7.1
Disclosed:
Sep 12, 2024

CVE-2024-8529 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'

critical

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

CVSS:
10
Affected:
up to 4.2.7
Fixed in:
4.2.7.1
Disclosed:
Sep 11, 2024

CVE-2024-8529 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'

critical

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...

CVSS:
10
Affected:
up to 4.2.7
Fixed in:
4.2.7.1
Disclosed:
Sep 11, 2024

CVE-2024-8522 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.9

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.

Affected:
up to 4.2.6.9
Fixed in:
4.2.6.9
Disclosed:
Aug 26, 2024

CVE-2024-39641 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.9

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LearnPress: from n/a through 4.2.6.8.2.

Affected:
up to 4.2.6.9
Fixed in:
4.2.6.9
Disclosed:
Aug 13, 2024

CVE-2024-39642 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.9.4

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 4.2.6.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Affected:
up to 4.2.6.9.4
Fixed in:
4.2.6.9.4
Disclosed:
Aug 8, 2024

CVE-2024-7548 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter

high

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 4.2.6.9.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
8.8
Affected:
up to 4.2.6.9.3
Fixed in:
4.2.6.9.4
Disclosed:
Aug 7, 2024

CVE-2024-7548 on NVD →

LearnPress <= 4.2.6.8.2 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.8.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unaut...

CVSS:
5.4
Affected:
up to 4.2.6.8.2
Fixed in:
4.2.6.9
Disclosed:
Aug 1, 2024

CVE-2024-39642 on NVD →

LearnPress <= 4.2.6.8.2 - Cross-Site Request Forgery

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6.8.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted t...

CVSS:
4.3
Affected:
up to 4.2.6.8.2
Fixed in:
4.2.6.9
Disclosed:
Aug 1, 2024

CVE-2024-39641 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.9

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the 'render_content_block_template' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbi...

Affected:
up to 4.2.6.9
Fixed in:
4.2.6.9
Disclosed:
Jul 25, 2024

CVE-2024-6589 on NVD →

LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion

high

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the 'render_content_block_template' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary...

CVSS:
8.8
Affected:
up to 4.2.6.8.2
Fixed in:
4.2.6.9
Disclosed:
Jul 24, 2024

CVE-2024-6589 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.8.2

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user registration to creat...

Affected:
up to 4.2.6.8.2
Fixed in:
4.2.6.8.2
Disclosed:
Jul 2, 2024

CVE-2024-6088 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.8.2

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to registe...

Affected:
up to 4.2.6.8.2
Fixed in:
4.2.6.8.2
Disclosed:
Jul 2, 2024

CVE-2024-6099 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user registration to create a n...

CVSS:
5.3
Affected:
up to 4.2.6.8.1
Fixed in:
4.2.6.8.2
Disclosed:
Jul 1, 2024

CVE-2024-6088 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to register as...

CVSS:
5.3
Affected:
up to 4.2.6.8.1
Fixed in:
4.2.6.8.2
Disclosed:
Jul 1, 2024

CVE-2024-6099 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.3.1

unknown

[en] Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Affected:
up to 4.2.3.1
Fixed in:
4.2.3.1
Disclosed:
Jun 19, 2024

CVE-2023-36516 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.3.1

unknown

[en] Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Affected:
up to 4.2.3.1
Fixed in:
4.2.3.1
Disclosed:
Jun 19, 2024

CVE-2023-36515 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.8.1

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic information about w...

Affected:
up to 4.2.6.8.1
Fixed in:
4.2.6.8.1
Disclosed:
Jun 5, 2024

CVE-2024-5483 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic information about websit...

CVSS:
5.3
Affected:
up to 4.2.6.8
Fixed in:
4.2.6.8.1
Disclosed:
Jun 4, 2024

CVE-2024-5483 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.7

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.2.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

Affected:
up to 4.2.6.7
Fixed in:
4.2.6.7
Disclosed:
May 22, 2024

CVE-2024-4971 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.2.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 4.2.6.6
Fixed in:
4.2.6.7
Disclosed:
May 21, 2024

CVE-2024-4971 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.6

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_html’ parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-leve...

Affected:
up to 4.2.6.6
Fixed in:
4.2.6.6
Disclosed:
May 10, 2024

CVE-2024-4277 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.6

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

Affected:
up to 4.2.6.6
Fixed in:
4.2.6.6
Disclosed:
May 10, 2024

CVE-2024-4434 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.6

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on...

Affected:
up to 4.2.6.6
Fixed in:
4.2.6.6
Disclosed:
May 10, 2024

CVE-2024-4444 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_html’ parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level acc...

CVSS:
6.4
Affected:
up to 4.2.6.5
Fixed in:
4.2.6.6
Disclosed:
May 9, 2024

CVE-2024-4277 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection

critical

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for...

CVSS:
9.8
Affected:
up to 4.2.6.5
Fixed in:
4.2.6.6
Disclosed:
May 9, 2024

CVE-2024-4434 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload

high

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to uplo...

CVSS:
8.8
Affected:
up to 4.2.6.5
Fixed in:
4.2.6.6
Disclosed:
May 9, 2024

CVE-2024-4397 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the s...

CVSS:
5.3
Affected:
up to 4.2.6.5
Fixed in:
4.2.6.6
Disclosed:
May 9, 2024

CVE-2024-4444 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.6

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to...

Affected:
up to 4.2.6.6
Fixed in:
4.2.6.6
Disclosed:
May 9, 2024

CVE-2024-4397 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.5

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...

Affected:
up to 4.2.6.5
Fixed in:
4.2.6.5
Disclosed:
Apr 19, 2024

CVE-2024-3560 on NVD →

LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 4.2.6.4
Fixed in:
4.2.6.5
Disclosed:
Apr 18, 2024

CVE-2024-3560 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.4

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.3 due to missing validation on a user controlled key when looking up order information. This makes it possible for authenticated attackers to obtain information o...

Affected:
up to 4.2.6.4
Fixed in:
4.2.6.4
Disclosed:
Apr 9, 2024

CVE-2024-1289 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.6.4

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, and Quiz title and content in all versions up to, and including, 4.2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Affected:
up to 4.2.6.4
Fixed in:
4.2.6.4
Disclosed:
Apr 9, 2024

CVE-2024-1463 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.0.1

unknown

[en] The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filter_users functions. This makes it possible for unauthenticated attackers to elevate their privileges to...

Affected:
up to 4.0.1
Fixed in:
4.0.1
Disclosed:
Apr 5, 2024

CVE-2024-2115 on NVD →

LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation

high

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filter_users functions. This makes it possible for unauthenticated attackers to elevate their privileges to that...

CVSS:
8.8
Affected:
up to 4.0.0
Fixed in:
4.0.1
Disclosed:
Apr 4, 2024

CVE-2024-2115 on NVD →

LearnPress <= 4.2.6.3 - Insecure Direct Object Reference

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.3 due to missing validation on a user controlled key when looking up order information. This makes it possible for authenticated attackers to obtain information on ord...

CVSS:
6.5
Affected:
up to 4.2.6.3
Fixed in:
4.2.6.4
Disclosed:
Apr 4, 2024

CVE-2024-1289 on NVD →

LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, and Quiz title and content in all versions up to, and including, 4.2.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with LP...

CVSS:
4.4
Affected:
up to 4.2.6.3
Fixed in:
4.2.6.4
Disclosed:
Apr 4, 2024

CVE-2024-1463 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.5.5

unknown

[en] The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 4.2.5.5
Fixed in:
4.2.5.5
Disclosed:
Jan 16, 2024

CVE-2023-5558 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.5.8

unknown

[en] The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlled key. This makes it possible for authenticated attackers, with subscriber-l...

Affected:
up to 4.2.5.8
Fixed in:
4.2.5.8
Disclosed:
Jan 11, 2024

CVE-2023-6223 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.5.8

unknown

[en] The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthentica...

Affected:
up to 4.2.5.8
Fixed in:
4.2.5.8
Disclosed:
Jan 11, 2024

CVE-2023-6567 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.5.8

unknown

[en] The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function...

Affected:
up to 4.2.5.8
Fixed in:
4.2.5.8
Disclosed:
Jan 11, 2024

CVE-2023-6634 on NVD →

LearnPress <= 4.2.5.7 - Command Injection

high

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with...

CVSS:
8.1
Affected:
up to 4.2.5.7
Fixed in:
4.2.5.8
Disclosed:
Jan 3, 2024

CVE-2023-6634 on NVD →

LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by

critical

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated a...

CVSS:
9.8
Affected:
up to 4.2.5.7
Fixed in:
4.2.5.8
Disclosed:
Jan 2, 2024

CVE-2023-6567 on NVD →

LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure

medium

The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlled key. This makes it possible for authenticated attackers, with subscriber-level...

CVSS:
4.3
Affected:
up to 4.2.5.7
Fixed in:
4.2.5.8
Disclosed:
Jan 2, 2024

CVE-2023-6223 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.5.4

unknown

Update the WordPress LearnPress plugin to the latest available version (at least 4.2.5.4). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress LearnPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML paylo...

Affected:
up to 4.2.5.4
Fixed in:
4.2.5.4
Disclosed:
Nov 8, 2023

LearnPress <= 4.2.5.3 - Reflected Cross-Site Scripting via add_internal_scripts_to_head

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_internal_scripts_to_head function in all versions up to and including 4.2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
up to 4.2.5.4
Fixed in:
4.2.5.4
Disclosed:
Nov 7, 2023

CVE-2023-5558 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.5.4

unknown

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the add_internal_scripts_to_head function in all versions up to and including 4.2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 4.2.5.4
Fixed in:
4.2.5.4
Disclosed:
Nov 7, 2023

LearnPress <= 4.2.3 - Missing Authorization

medium

The LearnPress plugin for WordPress is vulnerable to unauthorized access of user data due to a missing capability check on the search_users function in versions up to, and including, 4.2.3. This makes it possible for subscribers to enumerate users.

CVSS:
5.4
Affected:
up to 4.2.3.1
Fixed in:
4.2.3.1
Disclosed:
Jul 6, 2023

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.3.1

unknown

The LearnPress plugin for WordPress is vulnerable to unauthorized access of user data due to a missing capability check on the search_users function in versions up to, and including, 4.2.3. This makes it possible for subscribers to enumerate users.

Affected:
up to 4.2.3.1
Fixed in:
4.2.3.1
Disclosed:
Jul 6, 2023

LearnPress <= 4.2.3 - Missing Authorization to Information Exposure

high

The LearnPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on one of its functions in versions up to, and including, 4.2.3. This makes it possible for unauthenticated attackers to execute this function.

CVSS:
7.3
Affected:
up to 4.2.3
Fixed in:
4.2.3.1
Disclosed:
Jul 4, 2023

CVE-2023-36515 on NVD →

LearnPress <= 4.2.3 - Missing Authorization

medium

The LearnPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on one of its functions in versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
5.4
Affected:
up to 4.2.3
Fixed in:
4.2.3.1
Disclosed:
Jul 4, 2023

CVE-2023-36516 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.0

unknown

[en] SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Jan 24, 2023

CVE-2022-45820 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.0

unknown

[en] Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Jan 24, 2023

CVE-2022-47615 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.2.0

unknown

[en] SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Affected:
up to 4.2.0
Fixed in:
4.2.0
Disclosed:
Jan 24, 2023

CVE-2022-45808 on NVD →

LearnPress <= 4.1.7.3.2 - Unauthenticated SQL Injection

critical

The LearnPress plugin for WordPress is vulnerable to SQL Injection in versions up to and including 4.1.7.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries in...

CVSS:
9.8
Affected:
up to 4.1.7.3.2
Fixed in:
4.2.0
Disclosed:
Jan 20, 2023

CVE-2022-45808 on NVD →

LearnPress <= 4.1.7.3.2 - Unauthenticated Local File Inclusion

critical

The LearnPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.7.3.2 via the lp/v1/courses/archive-course rest API endpoint. This allows unauthenticated-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those...

CVSS:
9.8
Affected:
up to 4.1.7.3.2
Fixed in:
4.2.0
Disclosed:
Jan 20, 2023

CVE-2022-47615 on NVD →

LearnPress <= 4.1.7.3.2 - Authenticated (Subscriber+) SQL Injection

high

The LearnPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.7.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query passed via the learn_press_recent_courses and learn_press_featured_courses shortcodes. T...

CVSS:
8.8
Affected:
up to 4.1.7.3.2
Fixed in:
4.2.0
Disclosed:
Dec 20, 2022

CVE-2022-45820 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.7.2

unknown

[en] The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowle...

Affected:
up to 4.1.7.2
Fixed in:
4.1.7.2
Disclosed:
Oct 31, 2022

CVE-2022-3360 on NVD →

LearnPress <= 4.1.7.1 - Unauthenticated PHP Object Injection

critical

The LearnPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.7.1 via deserialization of untrusted input in a REST API endpoint available to unauthenticated users. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable pl...

CVSS:
9.8
Affected:
up to 4.1.7.1
Fixed in:
4.1.7.2
Disclosed:
Oct 3, 2022

CVE-2022-3360 on NVD →

LearnPress – WordPress LMS Plugin <= 4.1.6.7 - Reflected Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters related to pagination in versions up to, and including, 4.1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scr...

CVSS:
6.1
Affected:
up to 4.1.6.7
Fixed in:
4.1.6.8
Disclosed:
Jul 5, 2022

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.6.8

unknown

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters related to pagination in versions up to, and including, 4.1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scr...

Affected:
up to 4.1.6.8
Fixed in:
4.1.6.8
Disclosed:
Jul 5, 2022

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.6.7

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress LearnPress plugin (versions <= 4.1.6.6). Update the WordPress LearnPress plugin to the latest available version (at least 4.1.6.7).

Affected:
up to 4.1.6.7
Fixed in:
4.1.6.7
Disclosed:
Jun 21, 2022

LearnPress – WordPress LMS Plugin <= 4.1.6.5 - Reflected Cross-Site Scripting

medium

The LearnPress – WordPress LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.1.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
6.1
Affected:
up to 4.1.6.5
Fixed in:
4.1.6.6
Disclosed:
Jun 14, 2022

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.6.6

unknown

The LearnPress – WordPress LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.1.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

Affected:
up to 4.1.6.6
Fixed in:
4.1.6.6
Disclosed:
Jun 14, 2022

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.6

unknown

[en] The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Apr 11, 2022

CVE-2022-0271 on NVD →

LearnPress <= 4.1.5 - Reflected Cross-Site Scripting

medium

The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Mar 16, 2022

CVE-2022-0271 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.5

unknown

[en] Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result...

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Feb 28, 2022

CVE-2022-0377 on NVD →

LearnPress <= 4.1.4.1 - Arbitrary Image Renaming

medium

Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming and cropping of the image. As a result of th...

CVSS:
4.3
Affected:
up to 4.1.4.1
Fixed in:
4.1.5
Disclosed:
Jan 26, 2022

CVE-2022-0377 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.5

unknown

[en] The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Dec 13, 2021

CVE-2021-24951 on NVD →

LearnPress <= 4.1.3 - Authenticated SQL Injection

critical

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

CVSS:
9.8
Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Nov 9, 2021

CVE-2021-24951 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.3.2

unknown

[en] The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and incl...

Affected:
up to 4.1.3.2
Fixed in:
4.1.3.2
Disclosed:
Oct 21, 2021

CVE-2021-39348 on NVD →

LearnPress <= 4.1.3.1 - Stored Cross-Site Scripting via $custom_profile

medium

The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including...

CVSS:
5.5
Affected:
up to 4.1.3.1
Fixed in:
4.1.3.2
Disclosed:
Oct 18, 2021

CVE-2021-39348 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.5

unknown

[en] The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Oct 18, 2021

CVE-2021-24702 on NVD →

LearnPress <= 4.1.3 - Authenticated Stored Cross-Site Scripting

medium

The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed

CVSS:
4.8
Affected:
up to 4.1.3
Fixed in:
4.1.3.1
Disclosed:
Sep 20, 2021

CVE-2021-24702 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.6.9

unknown

[en] The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.

Affected:
up to 3.2.6.9
Fixed in:
3.2.6.9
Disclosed:
Jul 27, 2021

CVE-2020-11511 on NVD →

LearnPress <= 3.2.6.7 - SQL Injection

high

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

CVSS:
8.8
Affected:
up to 3.2.6.7
Fixed in:
3.2.6.8
Disclosed:
Jul 19, 2021

CVE-2020-6010 on NVD →

LearnPress – WordPress LMS Plugin <= 3.2.7.2 - SQL Injection

high

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 3.2.7.2, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the IP parameter found in the duplicator functionality. This can be exploit by contributor+...

CVSS:
8.8
Affected:
up to 3.2.7.2
Fixed in:
3.2.7.3
Disclosed:
Oct 5, 2020

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.7.3

unknown

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 3.2.7.2, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the IP parameter found in the duplicator functionality. This can be exploit by contributor+...

Affected:
up to 3.2.7.3
Fixed in:
3.2.7.3
Disclosed:
Oct 5, 2020

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.7.3

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress LearnPress plugin (versions <= 3.2.7.2).

Affected:
up to 3.2.7.3
Fixed in:
3.2.7.3
Disclosed:
Sep 9, 2020

LearnPress <= 3.2.7.2 - Reflected Cross-Site Scripting

medium

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.7.2.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully tr...

CVSS:
6.1
Affected:
up to 3.2.7.3
Fixed in:
3.2.7.3
Disclosed:
Sep 8, 2020

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.7.3

unknown

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.7.2.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully tr...

Affected:
up to 3.2.7.3
Fixed in:
3.2.7.3
Disclosed:
Sep 8, 2020

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.6.8

unknown

[en] LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

Affected:
up to 3.2.6.8
Fixed in:
3.2.6.8
Disclosed:
Apr 30, 2020

CVE-2020-6010 on NVD →

LearnPress <= 3.2.6.8 - Privilege Escalation via accept-to-be-teacher action parameter

high

The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.

CVSS:
8.1
Affected:
up to 3.2.6.8
Fixed in:
3.2.6.9
Disclosed:
Apr 20, 2020

CVE-2020-11511 on NVD →

LearnPress <= 3.2.6.8 - Authenticated Page Creation and Status Modification

high

Versions below 3.2.6.9 allow an attacker to publish or trash any existing post or page, or even set it to a nonexistent status, at which point it would no longer appear on the site or be accessible from wp-admin, and could only be recovered by modifying its status in the database.

CVSS:
7.1
Affected:
up to 3.2.6.8
Fixed in:
3.2.6.9
Disclosed:
Apr 19, 2020

CVE-2020-11510 on NVD →

LearnPress <= 3.2.6.6 - Privilege Escalation

high

be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role to an instructo...

CVSS:
7.1
Affected:
up to 3.2.6.6
Fixed in:
3.2.6.8
Disclosed:
Mar 16, 2020

CVE-2020-7916 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.6.8

unknown

[en] be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role to an inst...

Affected:
up to 3.2.6.8
Fixed in:
3.2.6.8
Disclosed:
Mar 16, 2020

CVE-2020-7916 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.1.0

unknown

[en] Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Jan 9, 2019

CVE-2018-16173 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.1.0

unknown

[en] Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Jan 9, 2019

CVE-2018-16174 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.1.0

unknown

[en] SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Jan 9, 2019

CVE-2018-16175 on NVD →

LearnPress <= 3.0.12 - Authenticated SQL Injection

high

SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

CVSS:
7.2
Affected:
up to 3.0.12
Fixed in:
3.1.0
Disclosed:
Nov 9, 2018

CVE-2018-16175 on NVD →

LearnPress <= 3.0.12 - Open Redirect

medium

Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS:
6.1
Affected:
up to 3.0.12
Fixed in:
3.1.0
Disclosed:
Nov 9, 2018

CVE-2018-16174 on NVD →

LearnPress <= 3.0.12 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 3.0.12
Fixed in:
3.1.0
Disclosed:
Nov 9, 2018

CVE-2018-16173 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.6.9

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.2.6.9
Fixed in:
3.2.6.9

CVE-2020-11510 on NVD →

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 4.1.6.7

unknown

The plugin does not escape some URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 4.1.6.7
Fixed in:
4.1.6.7

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.7.3

unknown

Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.

Affected:
up to 3.2.7.3
Fixed in:
3.2.7.3

LearnPress &#8211; WordPress LMS Plugin [learnpress] < 3.2.6.7

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 3.2.6.7
Fixed in:
3.2.6.7

CVE-2020-7917 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database