plugin

Learnpress Import Export Vulnerabilities

15 known security issues reported for the Learnpress Import Export WordPress plugin. Most recent disclosed Jun 5, 2026.

1 critical 1 high 7 medium

Running Learnpress Import Export on your site? Check whether your installed version is affected.

Scan your site free

LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter

medium

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read th...

CVSS:
4.9
Affected:
up to 4.1.4
Fixed in:
4.1.5
Disclosed:
Jun 5, 2026

CVE-2026-7565 on NVD →

LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload

medium

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP cha...

CVSS:
6.6
Affected:
up to 4.1.4
Fixed in:
4.1.5
Disclosed:
Jun 5, 2026

CVE-2026-7566 on NVD →

LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Course Deletion

medium

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to delete course th...

CVSS:
4.8
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Feb 11, 2026

CVE-2026-1787 on NVD →

LearnPress Export Import &#8211; WordPress extension for LearnPress [learnpress-import-export] <= 4.0.9 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows PHP Local File Inclusion.This issue affects LearnPress Export Import: from n/a through <= 4.0.9.

Affected:
up to 4.0.9
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-60200 on NVD →

LearnPress Export Import &#8211; WordPress extension for LearnPress [learnpress-import-export] <= 4.0.9 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows Reflected XSS.This issue affects LearnPress Export Import: from n/a through <= 4.0.9.

Affected:
up to 4.0.9
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49992 on NVD →

LearnPress Export Import <= 4.0.9 - Reflected Cross-Site Scripting

medium

The LearnPress Export Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 4.0.9
Fixed in:
4.1.0
Disclosed:
Jul 22, 2025

CVE-2025-49992 on NVD →

LearnPress Export Import <= 4.1.2 - Unauthenticated Local File Inclusion

high

The LearnPress Export Import plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass ac...

CVSS:
8.1
Affected:
up to 4.1.2
Fixed in:
4.1.3
Disclosed:
Jul 21, 2025

CVE-2025-60200 on NVD →

LearnPress Export Import &#8211; WordPress extension for LearnPress [learnpress-import-export] < 4.0.5

unknown

[en] The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for...

Affected:
up to 4.0.5
Fixed in:
4.0.5
Disclosed:
Nov 15, 2024

CVE-2024-9609 on NVD →

LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting

medium

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unau...

CVSS:
6.1
Affected:
up to 4.0.4
Fixed in:
4.0.5
Disclosed:
Nov 14, 2024

CVE-2024-9609 on NVD →

LearnPress Export Import &#8211; WordPress extension for LearnPress [learnpress-import-export] < 4.0.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress Export Import allows Reflected XSS.This issue affects LearnPress Export Import: from n/a through 4.0.3.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Apr 18, 2024

CVE-2024-32588 on NVD →

LearnPress Export Import <= 4.0.3 - Reflected Cross-Site Scripting

medium

The LearnPress Export Import plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 4.0.3
Fixed in:
4.0.4
Disclosed:
Apr 16, 2024

CVE-2024-32588 on NVD →

LearnPress Export Import &#8211; WordPress extension for LearnPress [learnpress-import-export] < 4.0.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a through 4.0.3.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Apr 7, 2024

CVE-2024-31241 on NVD →

LearnPress Export Import <= 4.0.3 - Authenticated (Administrator+) SQL Injection

critical

The LearnPress Export Import plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
9.1
Affected:
up to 4.0.3
Fixed in:
4.0.4
Disclosed:
Apr 5, 2024

CVE-2024-31241 on NVD →

LearnPress Export Import &#8211; WordPress extension for LearnPress [learnpress-import-export] < 4.0.3

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThimPress LearnPress Export Import plugin <= 4.0.2 versions.

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
May 18, 2023

CVE-2023-30487 on NVD →

LearnPress - Export/Import Courses <= 4.0.2 - Reflected Cross-Site Scripting

medium

The LearnPress - Export/Import Courses plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learn-press-export-file-name' parameter in versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
5.4
Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Apr 17, 2023

CVE-2023-30487 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database