SecAlerts
t

thimpress

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 100 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 9, 2019 to present

100
Total CVEs
48
Critical+High
1
Exploited
27
Unpatched

Threat Assessment

Avg CVSS
7.1
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
27
Critical/High
Risk Level
38/100
low
⚠️ 1 Active Exploits🆕 4Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
21
High
27
Medium
52
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
2
<5%
34

Age Distribution

Common Weaknesses (CWE)

1
XSS
26
2
SQL Injection
16
3
CSRF
8
4
Path Traversal
5
5
Malicious File Upload
3

Most Affected Products

1. thimpress Learnpress Wordpress45
2. thimpress Wp Hotel Booking Wordpress12
3. thimpress LearnPress11
4. thimpress Wp Pipes Wordpress7
5. thimpress WP Pipes6

Recent Vulnerabilities

See more →
CVE-2026-92538
CVSS 6.1medium

LearnPress <= 4.4.7 - Reflected DOM-Based Cross-Site Scripting via 'orderby' Parameter

Oct 3, 2026🔧 No Patch
CVE-2026-39717
CVSS 4.3medium

WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability

Oct 2, 2026🔧 No Patch
CVE-2026-104403
CVSS 5.3medium

WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability

Oct 2, 2026🔧 No Patch
CVE-2026-93882
CVSS 7.5high

LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter

Oct 1, 2026🔧 No Patch
CVE-2026-7565
CVSS 4.9medium

LearnPress <= 4.1.4 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'import-user-file' Parameter

Jun 6, 2026🔧 No Patch
CVE-2026-7566
CVSS 6.6medium

LearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File Upload

Jun 6, 2026🔧 No Patch
CVE-2025-53346
CVSS 4.3medium

WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control Vulnerability

Jun 2, 2026🔧 No Patch
CVE-2025-53345
CVSS 8.8high

WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerability

Jun 2, 2026🔧 No Patch
CVE-2026-7648
CVSS 4.3EPSS 0%medium

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter

May 14, 2026🔧 No Patch
CVE-2026-4365
CVSS 9.1critical

LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion

Apr 14, 2026🔧 No Patch

Monitor thimpress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

thimpress Security Vulnerabilities & Risk Score | 100 CVEs | SecAlerts - SecAlerts