Vulnerabilities (CVE)

Filtered by vendor Thimpress Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-11511 1 Thimpress 1 Learnpress 2022-07-12 6.8 MEDIUM 8.1 HIGH
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
CVE-2020-6010 1 Thimpress 1 Learnpress 2020-05-05 6.5 MEDIUM 8.8 HIGH
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
CVE-2018-16175 1 Thimpress 1 Learnpress 2019-01-11 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.