Thimpress develops a focused line of WordPress educational and hospitality plugins, including LearnPress, WP Hotel Booking, Eduma, and related tools, serving a modestly represented but notably positioned niche in the WordPress ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the plugin architecture's exposure to both unauthenticated attackers and privilege-escalation vectors. The exposure concentrates across its learning-management and booking products and recurs through characteristic web-application weaknesses: cross-site scripting, SQL injection, missing authorization checks, cross-site request forgery, and path traversal, all endemic to plugins that handle user input, database queries, and file access without sufficient sanitization or capability gating. Defenders operating WordPress installations should inventory these plugins, treat their advisories as high-priority despite their niche scope, and apply patches promptly given the plugin architecture's direct execution in the web root. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thimpress over time
Signals from CVEs in this vendor scope (92 CVEs).
92 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8522HIGH The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint | Sep 12, 2024 | 7.5 | 83 | NO | YES |
CVE-2023-5652CRITICAL The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a functi | Nov 20, 2023 | 9.8 | 74 | NO | YES |
CVE-2020-6010HIGH LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | Apr 30, 2020 | 8.8 | 67 | NO | YES |
CVE-2024-4434CRITICAL The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to in | May 14, 2024 | 9.8 | 60 | NO | YES |
CVE-2023-6567HIGH The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escapin | Jan 11, 2024 | 7.5 | 60 | NO | YES |
CVE-2024-8529HIGH The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoin | Sep 12, 2024 | 7.5 | 50 | NO | YES |
CVE-2020-29047CRITICAL The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cook | Mar 3, 2021 | 9.8 | 49 | NO | YES |
CVE-2022-45808CRITICAL SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | Jan 26, 2023 | 9.8 | 44 | NO | YES |
CVE-2023-6634CRITICAL The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making | Jan 11, 2024 | 9.8 | 43 | NO | YES |
CVE-2022-47615CRITICAL Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | Jan 26, 2023 | 9.8 | 42 | NO | YES |
Signals from CVEs in this vendor scope (92 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thimpress.
Media articles that mention a CVE ID that affects a product developed by Thimpress — matched by CVE ID, not by vendor name.