Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thimpress

First CVE: Jan 9, 2019Active for: 8 yearsTotal CVEs: 92
50.6
VTI Score
TOP TARGET

Thimpress develops a focused line of WordPress educational and hospitality plugins, including LearnPress, WP Hotel Booking, Eduma, and related tools, serving a modestly represented but notably positioned niche in the WordPress ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the plugin architecture's exposure to both unauthenticated attackers and privilege-escalation vectors. The exposure concentrates across its learning-management and booking products and recurs through characteristic web-application weaknesses: cross-site scripting, SQL injection, missing authorization checks, cross-site request forgery, and path traversal, all endemic to plugins that handle user input, database queries, and file access without sufficient sanitization or capability gating. Defenders operating WordPress installations should inventory these plugins, treat their advisories as high-priority despite their niche scope, and apply patches promptly given the plugin architecture's direct execution in the web root. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
92
Total CVEs
More Total CVEs than 99% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thimpress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2019
7 years ago
Most Recent CVE
Jul 24, 2026
1 day ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (92 CVEs).

92 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-8522HIGH
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint
Sep 12, 20247.583NOYES
CVE-2023-5652CRITICAL
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a functi
Nov 20, 20239.874NOYES
CVE-2020-6010HIGH
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
Apr 30, 20208.867NOYES
CVE-2024-4434CRITICAL
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to in
May 14, 20249.860NOYES
CVE-2023-6567HIGH
The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escapin
Jan 11, 20247.560NOYES
CVE-2024-8529HIGH
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoin
Sep 12, 20247.550NOYES
CVE-2020-29047CRITICAL
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cook
Mar 3, 20219.849NOYES
CVE-2022-45808CRITICAL
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
Jan 26, 20239.844NOYES
CVE-2023-6634CRITICAL
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making
Jan 11, 20249.843NOYES
CVE-2022-47615CRITICAL
Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
Jan 26, 20239.842NOYES
View all 92 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products92 CVEs
58%
28%
14%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network92 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low88 (95.7%)
High4 (4.3%)
Unknown0 (0.0%)
User Interaction
None55 (59.8%)
Unknown0 (0.0%)
Required37 (40.2%)
Privileges Required
Low27 (29.3%)
High12 (13.0%)
None53 (57.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (92 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.3% of CVEs· 98th percentile
Nuclei
15 CVEs
16.3% of CVEs· 97th percentile
ExploitDB
3 CVEs
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thimpress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thimpress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thimpress's Products

View all 6 CNAs →

Top CWEs