Vulnerabilidades em ThimPress

107 resultados
CVE-2024-4444MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User RegistrationEPSS 0.7%CVE-2026-7565MEDIUMLearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' ParameterEPSS 0.6%CVE-2022-45355HIGHWordPress WP Pipes Plugin <= 1.33 is vulnerable to SQL Injection (SQLi)EPSS 0.6%CVE-2024-6088MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration BypassEPSS 0.6%CVE-2024-7548HIGHLearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order ParameterEPSS 0.6%CVE-2025-39470HIGHWordPress Ivy School theme <= 1.6.0 - Local File Inclusion VulnerabilityEPSS 0.6%CVE-2024-32588HIGHWordPress LearnPress Export Import plugin <= 4.0.3 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-30508MEDIUMWordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerabilityEPSS 0.5%CVE-2024-51582HIGHWordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2024-7717HIGHWP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL InjectionEPSS 0.5%CVE-2024-31241HIGHWordPress LearnPress Export Import plugin <= 4.0.3 - Auth. SQL Injection vulnerabilityEPSS 0.5%CVE-2025-24601CRITICALWordPress FundPress plugin <= 2.0.6 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-60227HIGHWordPress WP Pipes plugin <= 1.4.3 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-7566MEDIUMLearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File UploadEPSS 0.4%CVE-2025-64195HIGHWordPress Eduma theme <= 5.7.6 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2024-1463MEDIUMLearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-7648MEDIUMLearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' ParameterEPSS 0.4%CVE-2024-6099MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User RegistrationEPSS 0.4%CVE-2025-11372MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table ManipulationEPSS 0.4%CVE-2024-34415MEDIUMWordPress Thim Elementor Kit plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%