Записи ThimPress
71 опубликованных записей вендора thimpress.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 4,2 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 33,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')19
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')16
- CWE-862 Missing Authorization6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-502 Deserialization of Untrusted Data2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
71 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2023-5652Proof of concept | WP Hotel Booking < 2.0.8 - Unauthenticated SQLithimpress · wp hotel booking · CWE-89 | Критическая9,8 | — | 63,7 % | 20 нояб. 2023 г. |
50В плане | CVE-2020-6010Готовый эксплойт | LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Высокая8,8 | — | 49,2 % | 30 апр. 2020 г. |
50В плане | CVE-2024-4434Proof of concept | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injectionthimpress · learnpress · CWE-89 | Критическая9,8 | — | 36,9 % | 14 мая 2024 г. |
49В плане | CVE-2024-8522Готовый эксплойт | LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'thimpress · learnpress · CWE-89 | Высокая7,5 | — | 62,9 % | 12 сент. 2024 г. |
45В плане | CVE-2023-6567Proof of concept | LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_bythimpress · learnpress · CWE-89 | Высокая7,5 | — | 51,4 % | 11 янв. 2024 г. |
44В плане | CVE-2020-29047Proof of concept | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operatithimpress · wp hotel booking · CWE-502 | Критическая9,8 | — | 16,0 % | 3 мар. 2021 г. |
42В плане | CVE-2023-6634Proof of concept | LearnPress <= 4.2.5.7 - Command Injectionthimpress · learnpress · CWE-88 | Критическая9,8 | — | 8,5 % | 11 янв. 2024 г. |
41В плане | CVE-2022-47615Proof of concept | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusionthimpress · learnpress · CWE-434 | Критическая9,8 | — | 5,1 % | 26 янв. 2023 г. |
40В плане | CVE-2024-7855Эксплойта нет | WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Uploadthimpress · wp hotel booking · CWE-434 | Высокая8,8 | — | 17,7 % | 2 окт. 2024 г. |
40В плане | CVE-2022-45808Proof of concept | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Критическая9,8 | — | 4,3 % | 26 янв. 2023 г. |
40В плане | CVE-2024-3605Proof of concept | WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injectionthimpress · wp hotel booking · CWE-89 | Критическая9,8 | — | 4,2 % | 19 июн. 2024 г. |
39Наблюдать | CVE-2021-24951Эксплойта нет | LearnPress < 4.1.4 - Admin+ SQL Injectionthimpress · learnpress · CWE-89 | Критическая9,8 | — | 1,6 % | 13 дек. 2021 г. |
39Наблюдать | CVE-2024-30508Эксплойта нет | WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerabilitythimpress · wp hotel booking · CWE-862 | Критическая9,8 | — | 0,5 % | 29 мар. 2024 г. |
39Наблюдать | CVE-2025-28979Эксплойта нет | WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerabilitythimpress · wp pipes · CWE-98 | Критическая9,8 | — | 0,5 % | 14 авг. 2025 г. |
39Наблюдать | CVE-2023-36515Эксплойта нет | WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerabilitythimpress · learnpress · CWE-862 | Критическая9,8 | — | 0,4 % | 19 июн. 2024 г. |
39Наблюдать | CVE-2025-28982Эксплойта нет | WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerabilitythimpress · wp pipes · CWE-89 | Критическая9,8 | — | 0,4 % | 16 июл. 2025 г. |
36Наблюдать | CVE-2025-48267Эксплойта нет | WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerabilitythimpress · wp pipes · CWE-22 | Критическая9,1 | — | 0,5 % | 9 июн. 2025 г. |
35Наблюдать | CVE-2024-4397Эксплойта нет | LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Uploadthimpress · learnpress · CWE-434 | Высокая8,8 | — | 1,0 % | 14 мая 2024 г. |
35Наблюдать | CVE-2022-45820Эксплойта нет | WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injectionthimpress · learnpress · CWE-89 | Высокая8,8 | — | 1,0 % | 26 янв. 2023 г. |
35Наблюдать | CVE-2024-6589Эксплойта нет | LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusionthimpress · learnpress · CWE-98 | Высокая8,8 | — | 0,8 % | 25 июл. 2024 г. |
35Наблюдать | CVE-2024-51582Эксплойта нет | WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerabilitythimpress · wp hotel booking · CWE-35 | Высокая8,8 | — | 0,5 % | 4 нояб. 2024 г. |
35Наблюдать | CVE-2023-36516Эксплойта нет | WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerabilitythimpress · learnpress · CWE-862 | Высокая8,8 | — | 0,5 % | 19 июн. 2024 г. |
35Наблюдать | CVE-2024-7717Эксплойта нет | WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injectionthimpress · wp events manager · CWE-89 | Высокая8,8 | — | 0,5 % | 31 авг. 2024 г. |
35Наблюдать | CVE-2024-2115Эксплойта нет | LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalationthimpress · learnpress · CWE-352 | Высокая8,8 | — | 0,3 % | 5 апр. 2024 г. |
35Наблюдать | CVE-2024-39641Эксплойта нет | WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerabilitythimpress · learnpress · CWE-352 | Высокая8,8 | — | 0,2 % | 26 авг. 2024 г. |
- CVE-2023-565258В плане
WP Hotel Booking < 2.0.8 - Unauthenticated SQLi
КритическаяCVSS 9,8Proof of conceptEPSS 64 %thimpress · wp hotel booking20 нояб. 2023 г.
- CVE-2020-601050В плане
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
ВысокаяCVSS 8,8Готовый эксплойтEPSS 49 %thimpress · learnpress30 апр. 2020 г.
- CVE-2024-443450В плане
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 37 %thimpress · learnpress14 мая 2024 г.
- CVE-2024-852249В плане
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
ВысокаяCVSS 7,5Готовый эксплойтEPSS 63 %thimpress · learnpress12 сент. 2024 г.
- CVE-2023-656745В плане
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
ВысокаяCVSS 7,5Proof of conceptEPSS 51 %thimpress · learnpress11 янв. 2024 г.
- CVE-2020-2904744В плане
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operati
КритическаяCVSS 9,8Proof of conceptEPSS 16 %thimpress · wp hotel booking3 мар. 2021 г.
- CVE-2023-663442В плане
LearnPress <= 4.2.5.7 - Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 9 %thimpress · learnpress11 янв. 2024 г.
- CVE-2022-4761541В плане
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 5 %thimpress · learnpress26 янв. 2023 г.
- CVE-2024-785540В плане
WP Hotel Booking <= 2.1.2 - Authenticated (Subscriber+) Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 18 %thimpress · wp hotel booking2 окт. 2024 г.
- CVE-2022-4580840В плане
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 4 %thimpress · learnpress26 янв. 2023 г.
- CVE-2024-360540В плане
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
КритическаяCVSS 9,8Proof of conceptEPSS 4 %thimpress · wp hotel booking19 июн. 2024 г.
- CVE-2021-2495139Наблюдать
LearnPress < 4.1.4 - Admin+ SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %thimpress · learnpress13 дек. 2021 г.
- CVE-2024-3050839Наблюдать
WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %thimpress · wp hotel booking29 мар. 2024 г.
- CVE-2025-2897939Наблюдать
WordPress WP Pipes <= 1.4.3 - Local File Inclusion Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %thimpress · wp pipes14 авг. 2025 г.
- CVE-2023-3651539Наблюдать
WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %thimpress · learnpress19 июн. 2024 г.
- CVE-2025-2898239Наблюдать
WordPress WP Pipes plugin <= 1.4.3 - SQL Injection Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %thimpress · wp pipes16 июл. 2025 г.
- CVE-2025-4826736Наблюдать
WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerability
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %thimpress · wp pipes9 июн. 2025 г.
- CVE-2024-439735Наблюдать
LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thimpress · learnpress14 мая 2024 г.
- CVE-2022-4582035Наблюдать
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thimpress · learnpress26 янв. 2023 г.
- CVE-2024-658935Наблюдать
LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thimpress · learnpress25 июл. 2024 г.
- CVE-2024-5158235Наблюдать
WordPress WP Hotel Booking plugin <= 2.2.9 - Local File Inclusion vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thimpress · wp hotel booking4 нояб. 2024 г.
- CVE-2023-3651635Наблюдать
WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %thimpress · learnpress19 июн. 2024 г.
- CVE-2024-771735Наблюдать
WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %thimpress · wp events manager31 авг. 2024 г.
- CVE-2024-211535Наблюдать
LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %thimpress · learnpress5 апр. 2024 г.
- CVE-2024-3964135Наблюдать
WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %thimpress · learnpress26 авг. 2024 г.