Vulnerabilidades em thimpress
107 resultadosCVE-2024-4277MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html ParameterEPSS 0.3%CVE-2025-24725MEDIUMWordPress Thim Elementor Kit Plugin <= 1.2.8 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2026-27065CRITICALWordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerabilityEPSS 0.3%CVE-2021-36852MEDIUMWordPress WP Hotel Booking plugin <= 1.10.5 - Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.3%CVE-2024-3560MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-4333MEDIUMLearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode AttributeEPSS 0.3%CVE-2024-12370MEDIUMWP Hotel Booking <= 2.1.5 - Missing AuthorizationEPSS 0.3%CVE-2025-53345HIGHWordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerabilityEPSS 0.3%CVE-2024-4971MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id ParameterEPSS 0.3%CVE-2025-14802MEDIUMLearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material DeletionEPSS 0.3%CVE-2024-13599MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson NameEPSS 0.3%CVE-2024-35697HIGHWordPress Eduma theme <= 5.4.7 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-2115HIGHLearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege EscalationEPSS 0.3%CVE-2026-25002HIGHWordPress LearnPress – Sepay Payment plugin <= 4.0.0 - Broken Authentication vulnerabilityEPSS 0.3%CVE-2026-3225MEDIUMLearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer DeletionEPSS 0.3%CVE-2026-1870MEDIUMThim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course DisclosureEPSS 0.3%CVE-2025-14075MEDIUMWP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' ParameterEPSS 0.3%CVE-2025-57987MEDIUMWordPress WP Events Manager Plugin <= 2.2.1 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2025-22312MEDIUMWordPress Thim Elementor Kit plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-24740MEDIUMWordPress Learnpress plugin <= 4.2.7.1 - Open Redirection vulnerabilityEPSS 0.2%