Vulnerability index

Browse CVEs

58 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Pipes HIGH 8.6
CVE-2025-60227

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.Thi…

Fix: after 1.4.3
Fix from $1,950 2025-10-22
Wp Pipes MEDIUM 6.1
CVE-2025-28977

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS. This i…

Fix: after 1.4.3
Fix from $1,600 2025-08-20
Wp Pipes CRITICAL 9.8
CVE-2025-28979

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PH…

Fix: after 1.4.3
Fix from $2,300 2025-08-14
Wp Pipes CRITICAL 9.8
CVE-2025-28982

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This i…

Fix: after 1.4.3
Fix from $2,300 2025-07-16
Wp Pipes CRITICAL 9.1
CVE-2025-48267

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue …

Fix: 1.4.3+
Fix from $2,300 2025-06-09
Wp Pipes MEDIUM 6.5
CVE-2025-47664

Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a thro…

Fix: after 1.4.3
Fix from $1,600 2025-05-07
Learnpress MEDIUM 5.4
CVE-2024-13599

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5…

Fix: 4.2.7.5.1+
Fix from $1,600 2025-01-25
Wp Hotel Booking MEDIUM 5.3
CVE-2024-12370

The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in a…

Fix: 2.1.6+
Fix from $1,600 2025-01-17
Wp Pipes MEDIUM 6.1
CVE-2024-12283

The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 …

Fix: 1.4.2+
Fix from $1,600 2024-12-11
Learnpress MEDIUM 5.3
CVE-2024-11868

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.…

Fix: 4.2.7.4+
Fix from $1,600 2024-12-10
Learnpress Export Import MEDIUM 6.1
CVE-2024-9609

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learn…

Fix: 4.0.5+
Fix from $1,600 2024-11-15
Wp Hotel Booking HIGH 8.8
CVE-2024-51582

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel …

Fix: after 2.1.4
Fix from $1,950 2024-11-04
Wp Hotel Booking HIGH 8.8
CVE-2024-7855EPSS 18%

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function…

Fix: 2.1.3+
Fix from $1,950 2024-10-02
Learnpress HIGH 7.5
CVE-2024-8522EPSS 63%

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpres…

Fix: 4.2.7.1+
Fix from $1,950 2024-09-12
Learnpress HIGH 7.5
CVE-2024-8529EPSS 12%

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/…

Fix: 4.2.7.1+
Fix from $1,950 2024-09-12
Wp Events Manager HIGH 8.8
CVE-2024-7717

The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, …

Fix: 2.2.0+
Fix from $1,950 2024-08-31
Learnpress HIGH 8.8
CVE-2024-39641

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.

Fix: 4.2.6.9+
Fix from $1,950 2024-08-26
Learnpress MEDIUM 6.5
CVE-2024-7548

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to,…

Fix: 4.2.6.9.4+
Fix from $1,600 2024-08-08
Learnpress HIGH 8.8
CVE-2024-6589

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via …

Fix: after 4.2.6.8.2
Fix from $1,950 2024-07-25
Learnpress MEDIUM 5.3
CVE-2024-6088

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the '…

Fix: 4.2.6.8.2+
Fix from $1,600 2024-07-02
Learnpress MEDIUM 5.3
CVE-2024-6099

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and includ…

Fix: 4.2.6.8.2+
Fix from $1,600 2024-07-02
Wp Hotel Booking CRITICAL 9.8
CVE-2024-3605

The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/rooms/search-rooms REST API en…

Fix: after 2.1.0
Fix from $2,300 2024-06-20
Learnpress HIGH 8.8
CVE-2023-36516

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Fix: 4.2.3.1+
Fix from $1,950 2024-06-19
Learnpress CRITICAL 9.8
CVE-2023-36515

Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.

Fix: 4.2.3.1+
Fix from $2,300 2024-06-19
Eduma MEDIUM 6.1
CVE-2024-35697

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThimPress Eduma allows Reflected XSS.Thi…

Fix: 5.4.8+
Fix from $1,600 2024-06-08
Learnpress MEDIUM 5.3
CVE-2024-5483

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.…

Fix: 4.2.6.8.1+
Fix from $1,600 2024-06-05
Learnpress MEDIUM 5.4
CVE-2024-4971

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up …

Fix: 4.2.6.7+
Fix from $1,600 2024-05-22
Learnpress MEDIUM 6.5
CVE-2024-4444

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. Th…

Fix: 4.2.6.6+
Fix from $1,600 2024-05-14
Learnpress CRITICAL 9.8
CVE-2024-4434EPSS 37%

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, a…

Fix: 4.2.6.6+
Fix from $2,300 2024-05-14
Learnpress HIGH 8.8
CVE-2024-4397

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_p…

Fix: 4.2.6.6+
Fix from $1,950 2024-05-14