SecAlerts
thimpress logo

thimpress

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 96 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 9, 2019 to present

96
Total CVEs
47
Critical+High
1
Exploited
26
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
26
Critical/High
Risk Level
43/100
medium
⚠️ 1 Active Exploits

Severity Distribution

Critical
21
High
26
Medium
49
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
2
<5%
34

Age Distribution

Common Weaknesses (CWE)

1
XSS
25
2
SQL Injection
16
3
CSRF
8
4
Path Traversal
5
5
Malicious File Upload
3

Most Affected Products

1. thimpress Learnpress Wordpress45
2. thimpress Wp Hotel Booking Wordpress12
3. thimpress LearnPress7
4. thimpress Wp Pipes Wordpress7
5. thimpress WP Pipes6

Recent Vulnerabilities

See more →
CVE-2026-7565
CVSS 4.9medium

LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter

6/6/2026🔧 No Patch
CVE-2026-7566
CVSS 6.6medium

LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload

6/6/2026🔧 No Patch
CVE-2025-53346
CVSS 4.3medium

WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control Vulnerability

6/2/2026🔧 No Patch
CVE-2025-53345
CVSS 8.8high

WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerability

6/2/2026🔧 No Patch
CVE-2026-7648
CVSS 4.3EPSS 0%medium

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter

5/14/2026🔧 No Patch
CVE-2026-4365
CVSS 9.1critical

LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion

4/14/2026🔧 No Patch
CVE-2026-4333
CVSS 6.4EPSS 0%medium

LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute

4/8/2026🔧 No Patch
CVE-2026-3225
CVSS 4.3medium

LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion

3/23/2026🔧 No Patch
CVE-2026-27065
CVSS 9.8critical

WordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerability

3/19/2026🔧 No Patch
CVE-2025-53344
CVSS 4.3medium

WordPress Thim Core Plugin <= 2.3.3 - Cross Site Request Forgery (CSRF) Vulnerability

1/5/2026🔧 No Patch

Monitor thimpress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.