Learnpress

WordPress plugin · learnpress · WordPress.org ↗
0
Critical
2
High
13
Known total
0
Unfixed
Running Learnpress on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.1
LearnPress < 4.4.7 - Reflected XSS via 'skin' Parameter
CVE.org
>=4.2.6.4, <4.4.7 v4.4.7 CVE-2026-86444 Sep 16, 2026
HIGH
CVSS 7.1
LearnPress < 4.4.1 - Reflected XSS via c_search
CVE.org
>=0, <4.4.1 v4.4.1 CVE-2026-12970 Jul 20, 2026
MEDIUM
CVSS 5.3
LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajax
CVE.org
>=4.2.9, <4.4.7 v4.4.7 CVE-2026-86445 Sep 16, 2026
MEDIUM
CVSS 5.3
LearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajax
CVE.org
>=4.4.6, <4.4.7 v4.4.7 CVE-2026-86447 Sep 16, 2026
MEDIUM
CVSS 5.3
LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API
CVE.org
>=4.2.7.1, <4.4.7 v4.4.7 CVE-2026-86449 Sep 16, 2026
MEDIUM
CVSS 5.1
LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles
CVE.org
>=0, <4.4.6 v4.4.6 CVE-2026-82024 Sep 3, 2026
MEDIUM
CVSS 5.3
LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert
CVE.org
>=0, <4.4.6 v4.4.6 CVE-2026-82023 Sep 3, 2026
MEDIUM
CVSS 5.3
LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure
CVE.org
>=0, <4.0.3 v4.0.3 CVE-2026-78125 Aug 27, 2026
MEDIUM
CVSS 6.5
LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant
CVE.org
>=0, <4.4.4 v4.4.4 CVE-2026-12976 Aug 12, 2026
MEDIUM
CVSS 5.3
LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API
CVE.org
>=0, <4.3.7 v4.3.7 CVE-2026-8383 Jun 17, 2026
LOW
CVSS 3.7
LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST Endpoint
CVE.org
>=4.4.3, <4.4.7 v4.4.7 CVE-2026-86446 Sep 17, 2026
LOW
CVSS 3.7
LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order
CVE.org
>=4.3.2.8, <4.4.7 v4.4.7 CVE-2026-86448 Sep 16, 2026
LOW
CVSS 2.2
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
CVE.org
>=0, <4.4.4 v4.4.4 CVE-2026-12971 Aug 10, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.