CVE-2026-104670
- EPSS 0.18%
- Veröffentlicht 06.10.2026 08:35:16
- Zuletzt bearbeitet 06.10.2026 15:04:25
Unauthenticated Cross Site Scripting (XSS) in LearnPress <= 4.4.9 versions.
CVE-2026-105397
- EPSS 0.17%
- Veröffentlicht 05.10.2026 15:11:23
- Zuletzt bearbeitet 07.10.2026 21:17:11
LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit ...
CVE-2026-92538
- EPSS 0.21%
- Veröffentlicht 03.10.2026 03:25:45
- Zuletzt bearbeitet 06.10.2026 15:04:52
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' parameter in all versions up to, and including, 4.4.7 due to insufficient input ...
CVE-2026-39717
- EPSS 0.15%
- Veröffentlicht 02.10.2026 14:49:50
- Zuletzt bearbeitet 02.10.2026 17:52:32
Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.
CVE-2026-104403
- EPSS 0.2%
- Veröffentlicht 02.10.2026 09:55:28
- Zuletzt bearbeitet 03.10.2026 16:16:34
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.
CVE-2026-93882
- EPSS 0.36%
- Veröffentlicht 01.10.2026 07:40:22
- Zuletzt bearbeitet 03.10.2026 16:16:44
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback e...
CVE-2026-12230
- EPSS 0.2%
- Veröffentlicht 08.09.2026 11:30:00
- Zuletzt bearbeitet 09.09.2026 17:17:15
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insufficient input s...
CVE-2026-82024
- EPSS 0.14%
- Veröffentlicht 03.09.2026 18:00:08
- Zuletzt bearbeitet 08.09.2026 20:18:59
LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answ...
CVE-2026-82023
- EPSS 0.18%
- Veröffentlicht 03.09.2026 18:00:03
- Zuletzt bearbeitet 08.09.2026 20:18:59
LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a missing owner...
CVE-2026-77823
- EPSS 0.35%
- Veröffentlicht 01.09.2026 04:27:52
- Zuletzt bearbeitet 01.09.2026 20:47:54
The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient escaping on the user supplied parameter and lack o...