SecAlerts
L

LearnPress

Security Risk Profile

35
/100
low

Security Risk Score

Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 12, 2024 to present

12
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
5.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
35/100
low
📈 2 in Last 30 Days

Severity Distribution

Critical
0
High
2
Medium
10
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
XSS
6
2
Infoleak
3

Most Affected Products

1. LearnPress LearnPress5
2. thimpress Learnpress Wordpress5
3. LearnPress LearnPress – WordPress LMS Plugin3
4. LearnPress WordPress plugin1
5. LearnPress LearnPress WordPress plugin1

Recent Vulnerabilities

See more →
CVE-2026-78125
CVSS 5.3medium

LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure

Aug 27, 2026🔧 No Patch
CVE-2026-75982
CVSS 4.4medium

LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter

Aug 25, 2026🔧 No Patch
CVE-2026-12976
CVSS 6.5medium

LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant

Aug 12, 2026🔧 No Patch
CVE-2026-12970
CVSS 7.1high

LearnPress < 4.4.1 - Reflected XSS via c_search

Jul 20, 2026🔧 No Patch
CVE-2026-13765
CVSS 7.5high

LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

Jul 17, 2026🔧 No Patch
CVE-2025-11368
CVSS 5.3medium

LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure

Nov 21, 2025🔧 No Patch
CVE-2025-11372
CVSS 6.5medium

LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation

Oct 18, 2025🔧 No Patch
CVE-2024-13128
CVSS 4.8medium

LearnPress – WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS

May 15, 2025🔧 No Patch
CVE-2024-13127
CVSS 4.8medium

LearnPress – WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS

May 15, 2025🔧 No Patch
CVE-2024-13599
CVSS 6.4medium

LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name

Jan 25, 2025

Monitor LearnPress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

LearnPress Security Vulnerabilities & Risk Score | 12 CVEs | SecAlerts - SecAlerts