VulnSea

ThimPress has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. Most affected products: learnpress (3), LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (2).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • learnpress 3
  • LearnPress – WordPress LMS Plugin for Create and Sell Online Courses 2
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ThimPress vulnerabilities

CVEs affecting ThimPress, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-104403Medium· 5.3
today

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.

▾ SunlitThimPress · learnpressvia NVD
CVE-2026-93882High· 7.5
yesterday

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items…

▾ Twilightthimpress · LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesvia NVD
CVE-2026-12230Medium· 6.4
3w ago

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insuffi…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter in all versions up to, and including, 4.3.9.1 due to insuffi…

▾ Sunlitthimpress · LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesEPSS 0.20%via NVD
CVE-2026-82024Medium· 5.4
4w ago

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz …

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz …

▾ SunlitThimPress · LearnPressEPSS 0.24%via NVD
CVE-2026-82023Medium· 4.3
4w ago

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a …

LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answers to quiz questions owned by other instructors by exploiting a …

▾ SunlitThimPress · LearnPressEPSS 0.29%via NVD
ThimPress vulnerabilities (CVEs) · VulnSea