vciy

CVEs we hold for Thimpress

Records whose assigning authority named Thimpress as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8502LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parametersthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-82024LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer TitlesThimPress LearnPress
CVE-2026-82023LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer InsertThimPress LearnPress
CVE-2026-77823LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameterthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-7648LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-75982LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameterthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-7566LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File…thimpress LearnPress – Backup & Migration Tool
CVE-2026-7565LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file'…thimpress LearnPress – Backup & Migration Tool
CVE-2026-66458WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerabilityThimPress RealPress
CVE-2026-57397WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerabilityThimPress. Coaching
CVE-2026-48865WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) vulnerabilityThimPress LearnPress
CVE-2026-4650FundPress <= 2.0.8 - Missing Authorization to Unauthenticated Arbitrary Donation Status Modification via…thimpress FundPress – WordPress Donation Plugin
CVE-2026-4365LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletionthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-4333LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attributethimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-3226LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggeringthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-3225LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletionthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-27065WordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerabilityThimPress BuilderPress
CVE-2026-27050WordPress RealPress plugin <= 1.1.0 - Cross Site Request Forgery (CSRF) vulnerabilityThimPress RealPress
CVE-2026-25002WordPress LearnPress – Sepay Payment plugin <= 4.0.0 - Broken Authentication vulnerabilityThimPress LearnPress – Sepay Payment
CVE-2026-24361WordPress LearnPress – Course Review plugin <= 4.1.9 - Cross Site Scripting (XSS) vulnerabilityThimPress LearnPress – Course Review
CVE-2026-1870Thim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course Disclosurethimpress Thim Kit for Elementor – Pre-built Templates &…
CVE-2026-1787LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Course Deletionthimpress LearnPress – Backup & Migration Tool
CVE-2026-15464WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode…thimpress WP Hotel Booking
CVE-2026-15094WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameterthimpress WP Hotel Booking
CVE-2026-13765LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-12732LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-12230LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css'thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-11988LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2026-11901WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal…thimpress WP Hotel Booking
CVE-2026-11392WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parametersthimpress WP Hotel Booking
CVE-2025-67594WordPress Thim Elementor Kit plugin <= 1.3.3 - Insecure Direct Object References (IDOR) vulnerabilityThimPress Thim Elementor Kit
CVE-2025-67573WordPress Sailing theme < 4.4.6 - Broken Access Control vulnerabilityThimPress Sailing
CVE-2025-67536WordPress LearnPress plugin <= 4.2.9.4 - Cross Site Scripting (XSS) vulnerabilityThimPress LearnPress
CVE-2025-67526WordPress Sailing theme < 4.4.6 - Local File Inclusion vulnerabilityThimPress Sailing
CVE-2025-66054WordPress LearnPress plugin <= 4.2.9.4 - Broken Access Control vulnerabilityThimPress LearnPress
CVE-2025-64195WordPress Eduma theme <= 5.7.6 - Local File Inclusion vulnerabilityThimPress Eduma
CVE-2025-64194WordPress Eduma theme <= 5.7.6 - Cross Site Scripting (XSS) vulnerabilityThimPress Eduma
CVE-2025-63013WordPress WP Hotel Booking plugin <= 2.2.7 - Sensitive Data Exposure vulnerabilityThimPress WP Hotel Booking
CVE-2025-63012WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Request Forgery (CSRF) vulnerabilityThimPress WP Hotel Booking
CVE-2025-63011WordPress WP Hotel Booking plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerabilityThimPress WP Hotel Booking
CVE-2025-60227WordPress WP Pipes plugin <= 1.4.3 - Arbitrary File Deletion vulnerabilityThimPress WP Pipes
CVE-2025-60200WordPress LearnPress Export Import plugin <= 4.1.2 - Local File Inclusion vulnerabilityThimPress LearnPress Export Import
CVE-2025-57987WordPress WP Events Manager Plugin <= 2.2.1 - Broken Access Control VulnerabilityThimPress WP Events Manager
CVE-2025-54721WordPress Resca theme <= 3.0.2 - Cross Site Scripting (XSS) vulnerabilityThimPress Resca
CVE-2025-53346WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control VulnerabilityThimPress Thim Core
CVE-2025-53345WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerabilityThimPress Thim Core
CVE-2025-53344WordPress Thim Core Plugin <= 2.3.3 - Cross Site Request Forgery (CSRF) VulnerabilityThimPress Thim Core
CVE-2025-49992WordPress LearnPress Export Import plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerabilityThimPress LearnPress Export Import
CVE-2025-48336WordPress Course Builder < 3.6.6 - PHP Object Injection VulnerabilityThimPress Course Builder
CVE-2025-48267WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion VulnerabilityThimPress WP Pipes
CVE-2025-47664WordPress WP Pipes <= 1.4.2 - Server Side Request Forgery (SSRF) VulnerabilityThimPress WP Pipes
CVE-2025-47448WordPress WP Hotel Booking plugin <= 2.1.9 - Cross Site Request Forgery (CSRF) VulnerabilityThimPress WP Hotel Booking
CVE-2025-39470WordPress Ivy School theme <= 1.6.0 - Local File Inclusion VulnerabilityThimPress Ivy School
CVE-2025-39460WordPress Eduma theme <= 5.6.4 - Broken Access Control vulnerabilityThimPress Eduma
CVE-2025-28982WordPress WP Pipes plugin <= 1.4.3 - SQL Injection VulnerabilityThimPress WP Pipes
CVE-2025-28979WordPress WP Pipes <= 1.4.3 - Local File Inclusion VulnerabilityThimPress WP Pipes
CVE-2025-28977WordPress WP Pipes Plugin <= 1.4.3 - Cross Site Scripting (XSS) VulnerabilityThimPress WP Pipes
CVE-2025-24740WordPress Learnpress plugin <= 4.2.7.1 - Open Redirection vulnerabilityThimPress LearnPress
CVE-2025-24725WordPress Thim Elementor Kit Plugin <= 1.2.8 - Broken Access Control vulnerabilityThimPress Thim Elementor Kit
CVE-2025-24601WordPress FundPress plugin <= 2.0.6 - PHP Object Injection vulnerabilityThimPress FundPress
CVE-2025-22739WordPress LearnPress plugin <= 4.2.7.5 - Broken Access Control vulnerabilityThimPress LearnPress
CVE-2025-22312WordPress Thim Elementor Kit plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerabilityThimPress Thim Elementor Kit
CVE-2025-14802LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2025-14798LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2025-14387LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2025-14075WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameterthimpress WP Hotel Booking
CVE-2025-13964LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modificationthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2025-13956LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposurethimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2025-13725Gutenberg Thim Blocks <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameterthimpress Thim Blocks
CVE-2025-11372LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulationthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2025-11368LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-9609LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scriptingthimpress LearnPress – Backup & Migration Tool
CVE-2024-8529LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-8522LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-7855WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Uploadthimpress WP Hotel Booking
CVE-2024-7717WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injectionthimpress WP Events Manager
CVE-2024-7548LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameterthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-6589LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusionthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-6099LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registrationthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-6088LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypassthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-5483LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON APIthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-51582WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerabilityThimPress WP Hotel Booking
CVE-2024-4971LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameterthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-4444LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registrationthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-4434LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injectionthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-4397LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Uploadthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-4329Thim Elementor Kit <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameterthimpress Thim Kit for Elementor – Pre-built Templates &…
CVE-2024-4277LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-39642WordPress LearnPress plugin <= 4.2.6.8.2 - Insecure Direct Object References (IDOR) vulnerabilityThimPress LearnPress
CVE-2024-39641WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerabilityThimPress LearnPress
CVE-2024-3605WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injectionthimpress WP Hotel Booking
CVE-2024-35697WordPress Eduma theme <= 5.4.7 - Reflected Cross Site Scripting (XSS) vulnerabilityThimPress Eduma
CVE-2024-3560LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scriptingthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-34415WordPress Thim Elementor Kit plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerabilityThimPress Thim Elementor Kit
CVE-2024-32588WordPress LearnPress Export Import plugin <= 4.0.3 - Reflected Cross Site Scripting (XSS) vulnerabilityThimPress LearnPress Export Import
CVE-2024-31241WordPress LearnPress Export Import plugin <= 4.0.3 - Auth. SQL Injection vulnerabilityThimPress LearnPress Export Import
CVE-2024-30508WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerabilityThimPress WP Hotel Booking
CVE-2024-2115LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalationthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-1463LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scriptingthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-13599LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson…thimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-13447WP Hotel Booking <= 2.1.6 - Missing Authorization to Authenticated (Subscriber+) User Email Retrievalthimpress WP Hotel Booking
CVE-2024-1289LearnPress <= 4.2.6.3 - Insecure Direct Object Referencethimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2024-12370WP Hotel Booking <= 2.1.5 - Missing Authorizationthimpress WP Hotel Booking
CVE-2024-12283WP Pipes <= 1.4.1 - Reflected Cross-Site Scripting via x1 Parameterthimpress WP Pipes
CVE-2024-11868LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST APIthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2023-6634LearnPress <= 4.2.5.7 - Command Injectionthimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2023-6567LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_bythimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2023-6223LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosurethimpress LearnPress – WordPress LMS Plugin for Create and…
CVE-2023-40009WordPress WP Pipes Plugin <= 1.4.0 is vulnerable to Cross Site Request Forgery (CSRF)ThimPress WP Pipes
CVE-2023-36516WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerabilityThimPress LearnPress
CVE-2023-36515WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerabilityThimPress LearnPress
CVE-2023-30487WordPress LearnPress Export Import Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)ThimPress LearnPress Export Import
CVE-2022-47615WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File InclusionThimPress LearnPress – WordPress LMS Plugin
CVE-2022-45820WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL InjectionThimPress LearnPress – WordPress LMS Plugin
CVE-2022-45808WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL InjectionThimPress LearnPress – WordPress LMS Plugin
CVE-2022-45355WordPress WP Pipes Plugin <= 1.33 is vulnerable to SQL Injection (SQLi)ThimPress WP Pipes
CVE-2021-36852WordPress WP Hotel Booking plugin <= 1.10.5 - Cross-Site Request Forgery (CSRF) vulnerabilityThimPress WP Hotel Booking
CVE-2020-36757WP Hotel Booking <= 1.10.1 - Cross-Site Request Forgery Bypassthimpress WP Hotel Booking
CVE-2018-16175no title heldThimPress LearnPress
CVE-2018-16174no title heldThimPress LearnPress
CVE-2018-16173no title heldThimPress LearnPress

121 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.