thimpress Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for thimpress products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
0
Beyond CISA KEV
4
Sensor Observed
1
Virtual Patch Available
0
thimpress KEVs Added by Year
4 thimpress KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-6567
The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including,... |
LearnPress – WordPress LMS Plugin | Confirmed | Not in CISA | 27 Jun 2026 |
|
CVE-2024-8522
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' |
LearnPress – WordPress LMS Plugin | High | Not in CISA | 12 Sep 2024 |
|
CVE-2023-6634
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function.... |
LearnPress – WordPress LMS Plugin | High | Not in CISA | 11 Jan 2024 |
|
CVE-2022-47615
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion |
LearnPress – WordPress LMS Plugin | High | Not in CISA | 24 Jan 2023 |
Common Vulnerability Classes (CWE)
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 2
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology