Vulnerability index

Browse CVEs

58 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Learnpress MEDIUM 5.4
CVE-2024-4277

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_html’ parameter in all versio…

Fix: 4.2.6.6+
Fix from $1,600 2024-05-14
Learnpress MEDIUM 5.4
CVE-2024-3560

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and …

Fix: 4.2.6.5+
Fix from $1,600 2024-04-19
Learnpress MEDIUM 5.4
CVE-2024-1289

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.…

Fix: 4.2.6.4+
Fix from $1,600 2024-04-09
Learnpress HIGH 8.8
CVE-2024-2115

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. T…

Fix: 4.0.1+
Fix from $1,950 2024-04-05
Wp Hotel Booking CRITICAL 9.8
CVE-2024-30508

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

Fix: 2.0.9.3+
Fix from $2,300 2024-03-29
Learnpress MEDIUM 6.1
CVE-2023-5558

The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected …

Fix: 4.2.5.5+
Fix from $1,600 2024-01-16
Learnpress CRITICAL 9.8
CVE-2023-6634EPSS 9%

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. Th…

Fix: after 4.2.5.7
Fix from $2,300 2024-01-11
Learnpress HIGH 7.5
CVE-2023-6567EPSS 51%

The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.…

Fix: 4.2.5.8+
Fix from $1,950 2024-01-11
Wp Hotel Booking CRITICAL 9.8
CVE-2023-5652EPSS 64%

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it…

Fix: 2.0.8+
Fix from $2,300 2023-11-20
Wp Hotel Booking MEDIUM 5.4
CVE-2023-5799

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles t…

Fix: 2.0.8+
Fix from $1,600 2023-11-20
Wp Hotel Booking MEDIUM 5.4
CVE-2023-5651

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be del…

Fix: 2.0.8+
Fix from $1,600 2023-11-20
Wp Pipes MEDIUM 6.5
CVE-2023-40009

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions.

Fix: after 1.4.0
Fix from $1,600 2023-10-03
Learnpress MEDIUM 6.1
CVE-2023-30487

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThimPress LearnPress Export Import plugin <= 4.0.2 versions.

Fix: after 4.0.2
Fix from $1,600 2023-05-18
Wp Pipes HIGH 7.2
CVE-2022-45355

Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.

Fix: after 1.33
Fix from $1,950 2023-03-29
Learnpress CRITICAL 9.8
CVE-2022-47615EPSS 5%

Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Fix: 4.2.0+
Fix from $2,300 2023-01-26
Learnpress HIGH 8.8
CVE-2022-45820

SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Fix: after 4.1.7.3.2
Fix from $1,950 2023-01-26
Learnpress CRITICAL 9.8
CVE-2022-45808

SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Fix: after 4.1.7.3.2
Fix from $2,300 2023-01-26
Learnpress HIGH 8.1
CVE-2022-3360

The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to…

Fix: 4.1.7.2+
Fix from $1,950 2022-10-31
Wp Hotel Booking HIGH 8.0
CVE-2021-36852

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.

Fix: after 1.10.5
Fix from $1,950 2022-08-22
Learnpress MEDIUM 6.1
CVE-2022-0271

The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_singl…

Fix: 4.1.6+
Fix from $1,600 2022-04-11
Learnpress CRITICAL 9.8
CVE-2021-24951

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicati…

Fix: 4.1.4+
Fix from $2,300 2021-12-13
Learnpress HIGH 8.1
CVE-2020-11511

The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-…

Fix: 3.2.6.9+
Fix from $1,950 2021-07-30
Wp Hotel Booking CRITICAL 9.8
CVE-2020-29047EPSS 16%

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the…

Fix: after 1.10.2
Fix from $2,300 2021-03-03
Learnpress HIGH 8.8
CVE-2020-6010EPSS 49%

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

Fix: after 3.2.6.7
Fix from $1,950 2020-04-30
Learnpress MEDIUM 6.5
CVE-2020-7916

be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teac…

Fix: after 3.2.6.5
Fix from $1,600 2020-03-16
Learnpress HIGH 7.2
CVE-2018-16175

SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via …

Fix: 3.1.0+
Fix from $1,950 2019-01-09
Learnpress MEDIUM 6.1
CVE-2018-16173

Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecifie…

Fix: 3.1.0+
Fix from $1,600 2019-01-09
Learnpress MEDIUM 6.1
CVE-2018-16174

Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishin…

Fix: 3.1.0+
Fix from $1,600 2019-01-09