LearnPress 4.4.3 - 4.4.6 - Unauthenticated Information Exposure
Medium
LearnPress <= 4.4.6 - Unauthenticated Information Exposure
Medium
LearnPress <= 4.4.6 - Unauthenticated Information Exposure
Medium
LearnPress <= 4.4.6 - Unauthenticated Information Exposure
Medium
LearnPress <= 4.4.6 - Unauthenticated Information Exposure
Medium
LearnPress <= 4.4.6 - Reflected Cross-Site Scripting
Medium
LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css'
Medium
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.4.5 - Missing Authorization
Medium
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.4.5 - Authenticated (Instructor+) Stored Cross-Site Scripting
Medium
LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
Medium
LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter
Medium
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses < 4.4.4 - Authenticated (Subscriber+) Information Exposure
Medium
LearnPress <= 4.4.3 - Authenticated (Instructor+) Server-Side Request Forgery
Medium
LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
High
LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
Medium
LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
Medium
LearnPress <= 4.4.0 - Reflected Cross-Site Scripting
Medium
LearnPress <= 4.3.6 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure
Medium
LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
Medium
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 - Reflected Cross-Site Scripting
Medium
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter
Medium
LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion
Critical
LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute
Medium
LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion
Medium
LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering
Medium
LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API
Medium
LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion
Medium
LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification
Medium
LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure
Medium
LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social
Medium
LearnPress <= 4.2.9.4 - Missing Authorization
Medium
LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure
Medium
LearnPress <= 4.2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Medium
LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation
Medium
LearnPress <= 4.2.7.5 - Missing Authorization
Medium
LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Medium
LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Medium
LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name
Medium
LearnPress <= 4.2.7.1 - Authenticated (Subscriber+) Open Redirect
Medium
LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API
Medium
LearnPress <= 4.2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Medium
LearnPress <= 4.2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Medium
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
Critical
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
Critical
LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter
High
LearnPress <= 4.2.6.8.2 - Cross-Site Request Forgery
Medium
LearnPress <= 4.2.6.8.2 - Authenticated (Subscriber+) Insecure Direct Object Reference
Medium
LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion
High
LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass
Medium
LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration
Medium
LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
Medium
LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Medium
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter
Medium
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
Critical
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration
Medium
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload
High
LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Medium
LearnPress <= 4.2.6.3 - Insecure Direct Object Reference
Medium
LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation
High
LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting
Medium
LearnPress <= 4.2.5.7 - Command Injection
High
LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure
Medium
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
Critical
LearnPress <= 4.2.5.3 - Reflected Cross-Site Scripting via add_internal_scripts_to_head
Medium
LearnPress <= 4.2.3 - Missing Authorization
Medium
July 6, 2023
Patched in ["4.2.3.1"]
LearnPress <= 4.2.3 - Missing Authorization
Medium
LearnPress <= 4.2.3 - Missing Authorization to Information Exposure
High
LearnPress <= 4.1.7.3.2 - Unauthenticated SQL Injection
Critical
LearnPress <= 4.1.7.3.2 - Unauthenticated Local File Inclusion
Critical
LearnPress <= 4.1.7.3.2 - Authenticated (Subscriber+) SQL Injection
High
LearnPress <= 4.1.7.1 - Unauthenticated PHP Object Injection
Critical
LearnPress – WordPress LMS Plugin <= 4.1.6.7 - Reflected Cross-Site Scripting
Medium
July 5, 2022
Patched in ["4.1.6.8"]
LearnPress – WordPress LMS Plugin <= 4.1.6.5 - Reflected Cross-Site Scripting
Medium
June 14, 2022
Patched in ["4.1.6.6"]
LearnPress <= 4.1.5 - Reflected Cross-Site Scripting
Medium
LearnPress <= 4.1.4.1 - Arbitrary Image Renaming
Medium
LearnPress <= 4.1.3 - Authenticated SQL Injection
Critical
LearnPress <= 4.1.3.1 - Stored Cross-Site Scripting via $custom_profile
Medium
LearnPress <= 4.1.3 - Authenticated Stored Cross-Site Scripting
Medium
LearnPress <= 3.2.6.7 - SQL Injection
High
LearnPress – WordPress LMS Plugin <= 3.2.7.2 - SQL Injection
High
October 5, 2020
Patched in ["3.2.7.3"]
LearnPress <= 3.2.7.2 - Reflected Cross-Site Scripting
Medium
September 8, 2020
Patched in ["3.2.7.3"]
LearnPress <= 3.2.6.8 - Privilege Escalation via accept-to-be-teacher action parameter
High
LearnPress <= 3.2.6.8 - Authenticated Page Creation and Status Modification
High
LearnPress <= 3.2.6.6 - Privilege Escalation
High
LearnPress <= 3.0.12 - Authenticated SQL Injection
High
LearnPress <= 3.0.12 - Open Redirect
Medium
LearnPress <= 3.0.12 - Cross-Site Scripting
Medium