VYPR

Learnpress

by WordPress

Source repositories

CVEs (67)

  • CVE-2022-0377MedFeb 28, 2022
    risk 0.24cvss 4.3epss 0.03

    Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to the server for renaming…

  • CVE-2023-6223MedJan 11, 2024
    risk 0.21cvss 4.3epss 0.00

    The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlled key. This makes it possible for…

  • CVE-2026-12971LowAug 10, 2026
    risk 0.14cvss 2.2epss 0.00

    The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

  • CVE-2026-12970HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a crafted…

  • CVE-2026-13765HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the…

  • CVE-2026-12732MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is due to insufficient input sanitization and output escaping in the FilterCourseTemplate::sections()…

  • CVE-2026-11988MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.3.9.1 via the 'userId' parameter due to missing validation on a user controlled key. This…

Page 4 of 4