Learnpress Wordpress Lms Plugin For Create And Sell Online Courses

WordPress plugin · learnpress-wordpress-lms-plugin-for-create-and-sell-online-courses · WordPress.org ↗
0
Critical
1
High
8
Known total
8
Unfixed
Running Learnpress Wordpress Lms Plugin For Create And Sell Online Courses on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.5
LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints
CVE.org
<=4.4.1 unfixed CVE-2026-13765 Jul 17, 2026
MEDIUM
CVSS 6.4
LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css'
CVE.org
<=4.3.9.1 unfixed CVE-2026-12230 Sep 8, 2026
MEDIUM
CVSS 4.9
LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
CVE.org
<=4.4.4 unfixed CVE-2026-77823 Sep 1, 2026
MEDIUM
CVSS 4.4
LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter
CVE.org
<=4.4.4 unfixed CVE-2026-75982 Aug 25, 2026
MEDIUM
CVSS 6.4
LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute
CVE.org
<=4.4.0 unfixed CVE-2026-12732 Jul 1, 2026
MEDIUM
CVSS 6.5
LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter
CVE.org
<=4.3.9.1 unfixed CVE-2026-11988 Jul 1, 2026
MEDIUM
CVSS 5.3
LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters
CVE.org
<=4.3.6 unfixed CVE-2026-8502 Jun 6, 2026
MEDIUM
CVSS 4.3
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter
CVE.org
<=4.3.5 unfixed CVE-2026-7648 May 14, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.