Learnpress
Vendor:
First CVE: Jan 9, 2019 · Active for 7 years
51
Total CVEs
More Total CVEs than 98% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Learnpress over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2019
7 years ago
Most Recent CVE
Jun 1, 2026
53 days ago
CVE Severity & Scoring
Learnpress51 CVEs
59%
29%
12%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network51 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (96.1%)
High2 (3.9%)
Unknown0 (0.0%)
User Interaction
None30 (58.8%)
Unknown0 (0.0%)
Required21 (41.2%)
Privileges Required
Low16 (31.4%)
High8 (15.7%)
None27 (52.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8522HIGH The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint | Sep 12, 2024 | 7.5 | 83 | NO | YES |
CVE-2020-6010HIGH LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | Apr 30, 2020 | 8.8 | 67 | NO | YES |
CVE-2024-4434CRITICAL The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to in | May 14, 2024 | 9.8 | 60 | NO | YES |
CVE-2023-6567HIGH The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escapin | Jan 11, 2024 | 7.5 | 60 | NO | YES |
CVE-2024-8529HIGH The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoin | Sep 12, 2024 | 7.5 | 50 | NO | YES |
CVE-2022-45808CRITICAL SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | Jan 26, 2023 | 9.8 | 44 | NO | YES |
CVE-2023-6634CRITICAL The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making | Jan 11, 2024 | 9.8 | 43 | NO | YES |
CVE-2022-47615CRITICAL Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. | Jan 26, 2023 | 9.8 | 42 | NO | YES |
CVE-2026-48865HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS.
This issue affects LearnPress: fro | Jun 1, 2026 | 7.1 | 32 | NO | NO |
CVE-2022-0271MEDIUM The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to | Apr 11, 2022 | 6.1 | 32 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (51 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
5.9% of CVEs· 97th percentile
Nuclei
11 CVEs
21.6% of CVEs· 98th percentile
ExploitDB
3 CVEs
5.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (51 CVEs).
Media Mentions
Signals from CVEs in this product scope (51 CVEs).
Top CNAs Publishing CVEs For Learnpress
Top CWEs
Versions
No cataloged versions.