ThimPress records
71 published records for vendor thimpress.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 4.2%
- Pre-auth RCE
- 3
- With a fix record
- 33.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')16
- CWE-862 Missing Authorization6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-502 Deserialization of Untrusted Data2
The weakness classes this vendor ships most often: where to look.
CWEAll records
71 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2023-5652Proof of concept | WP Hotel Booking < 2.0.8 - Unauthenticated SQLithimpress · wp hotel booking · CWE-89 | Critical9.8 | — | 63.7% | Nov 20, 2023 |
50Plan | CVE-2020-6010Weaponized | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | High8.8 | — | 49.2% | Apr 30, 2020 |
50Plan | CVE-2024-4434Proof of concept | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injectionthimpress · learnpress · CWE-89 | Critical9.8 | — | 36.9% | May 14, 2024 |
49Plan | CVE-2024-8522Weaponized | LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'thimpress · learnpress · CWE-89 | High7.5 | — | 62.9% | Sep 12, 2024 |
45Plan | CVE-2023-6567Proof of concept | LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_bythimpress · learnpress · CWE-89 | High7.5 | — | 51.4% | Jan 11, 2024 |
44Plan | CVE-2020-29047Proof of concept | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operatithimpress · wp hotel booking · CWE-502 | Critical9.8 | — | 16.0% | Mar 3, 2021 |
42Plan | CVE-2023-6634Proof of concept | LearnPress <= 4.2.5.7 - Command Injectionthimpress · learnpress · CWE-88 | Critical9.8 | — | 8.5% | Jan 11, 2024 |
41Plan | CVE-2022-47615Proof of concept | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusionthimpress · learnpress · CWE-434 | Critical9.8 | — | 5.1% | Jan 26, 2023 |
40Plan | CVE-2024-7855No exploit | WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Uploadthimpress · wp hotel booking · CWE-434 | High8.8 | — | 17.7% | Oct 2, 2024 |
40Plan | CVE-2022-45808Proof of concept | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Critical9.8 | — | 4.3% | Jan 26, 2023 |
40Plan | CVE-2024-3605Proof of concept | WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injectionthimpress · wp hotel booking · CWE-89 | Critical9.8 | — | 4.2% | Jun 19, 2024 |
39Monitor | CVE-2021-24951No exploit | LearnPress < 4.1.4 - Admin+ SQL Injectionthimpress · learnpress · CWE-89 | Critical9.8 | — | 1.6% | Dec 13, 2021 |
39Monitor | CVE-2024-30508No exploit | WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerabilitythimpress · wp hotel booking · CWE-862 | Critical9.8 | — | 0.5% | Mar 29, 2024 |
39Monitor | CVE-2025-28979No exploit | WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerabilitythimpress · wp pipes · CWE-98 | Critical9.8 | — | 0.5% | Aug 14, 2025 |
39Monitor | CVE-2023-36515No exploit | WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerabilitythimpress · learnpress · CWE-862 | Critical9.8 | — | 0.4% | Jun 19, 2024 |
39Monitor | CVE-2025-28982No exploit | WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerabilitythimpress · wp pipes · CWE-89 | Critical9.8 | — | 0.4% | Jul 16, 2025 |
36Monitor | CVE-2025-48267No exploit | WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerabilitythimpress · wp pipes · CWE-22 | Critical9.1 | — | 0.5% | Jun 9, 2025 |
35Monitor | CVE-2024-4397No exploit | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Uploadthimpress · learnpress · CWE-434 | High8.8 | — | 1.0% | May 14, 2024 |
35Monitor | CVE-2022-45820No exploit | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | High8.8 | — | 1.0% | Jan 26, 2023 |
35Monitor | CVE-2024-6589No exploit | LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusionthimpress · learnpress · CWE-98 | High8.8 | — | 0.8% | Jul 25, 2024 |
35Monitor | CVE-2024-51582No exploit | WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerabilitythimpress · wp hotel booking · CWE-35 | High8.8 | — | 0.5% | Nov 4, 2024 |
35Monitor | CVE-2023-36516No exploit | WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerabilitythimpress · learnpress · CWE-862 | High8.8 | — | 0.5% | Jun 19, 2024 |
35Monitor | CVE-2024-7717No exploit | WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injectionthimpress · wp events manager · CWE-89 | High8.8 | — | 0.5% | Aug 31, 2024 |
35Monitor | CVE-2024-2115No exploit | LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalationthimpress · learnpress · CWE-352 | High8.8 | — | 0.3% | Apr 5, 2024 |
35Monitor | CVE-2024-39641No exploit | WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerabilitythimpress · learnpress · CWE-352 | High8.8 | — | 0.2% | Aug 26, 2024 |
- CVE-2023-565258Plan
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
CriticalCVSS 9.8Proof of conceptEPSS 64%thimpress · wp hotel bookingNov 20, 2023
- CVE-2020-601050Plan
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
HighCVSS 8.8WeaponizedEPSS 49%thimpress · learnpressApr 30, 2020
- CVE-2024-443450Plan
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 37%thimpress · learnpressMay 14, 2024
- CVE-2024-852249Plan
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
HighCVSS 7.5WeaponizedEPSS 63%thimpress · learnpressSep 12, 2024
- CVE-2023-656745Plan
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
HighCVSS 7.5Proof of conceptEPSS 51%thimpress · learnpressJan 11, 2024
- CVE-2020-2904744Plan
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operati
CriticalCVSS 9.8Proof of conceptEPSS 16%thimpress · wp hotel bookingMar 3, 2021
- CVE-2023-663442Plan
LearnPress <= 4.2.5.7 - Command Injection
CriticalCVSS 9.8Proof of conceptEPSS 9%thimpress · learnpressJan 11, 2024
- CVE-2022-4761541Plan
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 5%thimpress · learnpressJan 26, 2023
- CVE-2024-785540Plan
WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 18%thimpress · wp hotel bookingOct 2, 2024
- CVE-2022-4580840Plan
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 4%thimpress · learnpressJan 26, 2023
- CVE-2024-360540Plan
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 4%thimpress · wp hotel bookingJun 19, 2024
- CVE-2021-2495139Monitor
LearnPress < 4.1.4 - Admin+ SQL Injection
CriticalCVSS 9.8No exploitEPSS 2%thimpress · learnpressDec 13, 2021
- CVE-2024-3050839Monitor
WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 1%thimpress · wp hotel bookingMar 29, 2024
- CVE-2025-2897939Monitor
WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerability
CriticalCVSS 9.8No exploitEPSS 0%thimpress · wp pipesAug 14, 2025
- CVE-2023-3651539Monitor
WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability
CriticalCVSS 9.8No exploitEPSS 0%thimpress · learnpressJun 19, 2024
- CVE-2025-2898239Monitor
WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerability
CriticalCVSS 9.8No exploitEPSS 0%thimpress · wp pipesJul 16, 2025
- CVE-2025-4826736Monitor
WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerability
CriticalCVSS 9.1No exploitEPSS 0%thimpress · wp pipesJun 9, 2025
- CVE-2024-439735Monitor
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload
HighCVSS 8.8No exploitEPSS 1%thimpress · learnpressMay 14, 2024
- CVE-2022-4582035Monitor
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
HighCVSS 8.8No exploitEPSS 1%thimpress · learnpressJan 26, 2023
- CVE-2024-658935Monitor
LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion
HighCVSS 8.8No exploitEPSS 1%thimpress · learnpressJul 25, 2024
- CVE-2024-5158235Monitor
WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability
HighCVSS 8.8No exploitEPSS 1%thimpress · wp hotel bookingNov 4, 2024
- CVE-2023-3651635Monitor
WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 1%thimpress · learnpressJun 19, 2024
- CVE-2024-771735Monitor
WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injection
HighCVSS 8.8No exploitEPSS 0%thimpress · wp events managerAug 31, 2024
- CVE-2024-211535Monitor
LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation
HighCVSS 8.8No exploitEPSS 0%thimpress · learnpressApr 5, 2024
- CVE-2024-3964135Monitor
WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability
HighCVSS 8.8No exploitEPSS 0%thimpress · learnpressAug 26, 2024