İçeriğe atla
Noroxi

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

learnpress · eklenti

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

63 bilinen açık

6 kritik · 32 kayıt giriş yapmadan sömürülebilir · 1 kayıt için resmî yama görünmüyor · 12 kayıt için istismar kodu yayımlanmış · son kayıt 2 Eki 2026

wordpress.org'da yayında · son sürüm 4.4.9.1 · son güncelleme 1 Eki 2026 · 70 bin+ kurulum

wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi

Güvenlik açıkları

  • CVE-2023-36515kimlik doğrulamasız≤ 4.2.3

    WordPress LearnPress plugin <= 4.2.3 - Unauthenticated Broken Access Control vulnerability

    Kritik 9.8
  • CVE-2024-4434kimlik doğrulamasız≤ 4.2.6.5

    LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection

    Kritik 9.8
  • CVE-2023-6634kimlik doğrulamasız≤ 4.2.5.7

    LearnPress <= 4.2.5.7 - Command Injection

    Kritik 9.8
  • CVE-2022-47615kimlik doğrulamasız≤ 4.1.7.3.2

    WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion

    Kritik 9.8
  • CVE-2022-45808kimlik doğrulamasız≤ 4.1.7.3.2

    WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection

    Kritik 9.8
  • CVE-2026-4365kimlik doğrulamasız≤ 4.3.2.8

    LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion

    Kritik 9.1
  • CVE-2024-39641kimlik doğrulamasız · tıklama gerekir≤ 4.2.6.8.2

    WordPress LearnPress plugin <= 4.2.6.8.2 - Cross Site Request Forgery (CSRF) vulnerability

    Yüksek 8.8
  • CVE-2024-2115kimlik doğrulamasız · tıklama gerekir≤ 4.0.0

    LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation

    Yüksek 8.8
  • CVE-2023-36516giriş gerekir≤ 4.2.3

    WordPress LearnPress plugin <= 4.2.3 - Authenticated Broken Access Control vulnerability

    Yüksek 8.8
  • CVE-2024-4397giriş gerekir≤ 4.2.6.5

    LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload

    Yüksek 8.8
  • CVE-2022-45820giriş gerekir≤ 4.1.7.3.2

    WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection

    Yüksek 8.8
  • CVE-2020-6010giriş gerekir

    LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

    Yüksek 8.8
  • CVE-2024-6589katılımcı+≤ 4.2.6.8.2

    LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion

    Yüksek 8.8
  • CVE-2020-11511kimlik doğrulamasız

    The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the a

    Yüksek 8.1
  • CVE-2026-93882kimlik doğrulamasız≤ 4.4.8

    LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter

    Yüksek 7.5
  • CVE-2026-13765kimlik doğrulamasız≤ 4.4.1

    LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

    Yüksek 7.5
  • CVE-2025-66054kimlik doğrulamasız≤ 4.2.9.4

    WordPress LearnPress plugin <= 4.2.9.4 - Broken Access Control vulnerability

    Yüksek 7.5
  • CVE-2024-8529kimlik doğrulamasız≤ 4.2.7

    LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'

    Yüksek 7.5
  • CVE-2024-8522kimlik doğrulamasız≤ 4.2.7

    LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'

    Yüksek 7.5
  • CVE-2023-6567kimlik doğrulamasız≤ 4.2.5.7

    LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by

    Yüksek 7.5
  • CVE-2018-16175yönetici

    SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL comm

    Yüksek 7.2
  • CVE-2026-48865kimlik doğrulamasız · tıklama gerekir≤ 4.3.6

    WordPress LearnPress plugin <= 4.3.6 - Reflected Cross Site Scripting (XSS) vulnerability

    Yüksek 7.1
  • CVE-2025-11372kimlik doğrulamasız≤ 4.2.9.3

    LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Table Manipulation

    Orta 6.5
  • CVE-2024-4444kimlik doğrulamasız≤ 4.2.6.5

    LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration

    Orta 6.5
  • CVE-2026-11988abone+≤ 4.3.9.1

    LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter

    Orta 6.5
  • CVE-2025-67536giriş gerekir≤ 4.2.9.4

    WordPress LearnPress plugin <= 4.2.9.4 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2024-39642giriş gerekir≤ 4.2.6.8.2

    WordPress LearnPress plugin <= 4.2.6.8.2 - Insecure Direct Object References (IDOR) vulnerability

    Orta 6.5
  • CVE-2020-7916giriş gerekir

    be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself

    Orta 6.5
  • CVE-2024-7548katılımcı+≤ 4.2.6.9.3

    LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter

    Orta 6.5
  • CVE-2026-12230katılımcı+≤ 4.3.9.1

    LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css'

    Orta 6.4
  • CVE-2026-12732katılımcı+≤ 4.4.0

    LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute

    Orta 6.4
  • CVE-2026-4333katılımcı+≤ 4.3.3

    LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute

    Orta 6.4
  • CVE-2018-16174kimlik doğrulamasız · tıklama gerekir

    Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduc

    Orta 6.1
  • CVE-2018-16173kimlik doğrulamasız · tıklama gerekir

    Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via u

    Orta 6.1
  • CVE-2025-14802giriş gerekir≤ 4.3.2.1

    LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion

    Orta 5.4
  • CVE-2024-13599giriş gerekir≤ 4.2.7.5

    LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name

    Orta 5.4
  • CVE-2024-1289giriş gerekir≤ 4.2.6.3

    LearnPress <= 4.2.6.3 - Insecure Direct Object Reference

    Orta 5.4
  • CVE-2024-4971katılımcı+≤ 4.2.6.6

    LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

    Orta 5.4
  • CVE-2024-4277katılımcı+≤ 4.2.6.5

    LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter

    Orta 5.4
  • CVE-2024-3560katılımcı+≤ 4.2.6.4

    LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Orta 5.4
  • CVE-2026-104403kimlik doğrulamasız≤ 4.4.9

    WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerability

    Orta 5.3
  • CVE-2026-8502kimlik doğrulamasız≤ 4.3.6

    LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters

    Orta 5.3
  • CVE-2025-14798kimlik doğrulamasız≤ 4.3.2.4

    LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API

    Orta 5.3
  • CVE-2025-13964kimlik doğrulamasız≤ 4.3.2

    LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification

    Orta 5.3
  • CVE-2025-13956kimlik doğrulamasız≤ 4.3.1

    LearnPress – WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure

    Orta 5.3
  • CVE-2025-11368kimlik doğrulamasız≤ 4.2.9.4

    LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure

    Orta 5.3
  • CVE-2025-22739kimlik doğrulamasız≤ 4.2.7.5

    WordPress LearnPress plugin <= 4.2.7.5 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2024-11868kimlik doğrulamasız≤ 4.2.7.3

    LearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API

    Orta 5.3
  • CVE-2024-6099kimlik doğrulamasız≤ 4.2.6.8.1

    LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration

    Orta 5.3
  • CVE-2024-6088kimlik doğrulamasız≤ 4.2.6.8.1

    LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass

    Orta 5.3
  • CVE-2024-5483kimlik doğrulamasız≤ 4.2.6.8

    LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API

    Orta 5.3
  • CVE-2026-82023giriş gerekir→ 4.4.6

    LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert

    Orta 5.3
  • CVE-2026-82024giriş gerekir→ 4.4.6

    LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles

    Orta 5.1
  • CVE-2026-77823yönetici≤ 4.4.4

    LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

    Orta 4.9
  • CVE-2024-1463yüksek yetki≤ 4.2.6.3

    LearnPress <= 4.2.6.3 - Authenticated(LP Instructor+) Stored Cross-Site Scripting

    Orta 4.8
  • CVE-2021-39348yönetici≤ 4.1.3.1

    LearnPress – WordPress LMS Plugin <= 4.1.3.1 Authenticated Stored Cross-Site Scripting

    Orta 4.8
  • CVE-2025-24740kimlik doğrulamasız · tıklama gerekir≤ 4.2.7.1

    WordPress Learnpress plugin <= 4.2.7.1 - Open Redirection vulnerability

    Orta 4.7
  • CVE-2026-75982editör+≤ 4.4.4

    LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter

    Orta 4.4
  • CVE-2026-39717giriş gerekiryama görünmüyor

    WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability

    Orta 4.3
  • CVE-2026-7648abone+≤ 4.3.5

    LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quanti

    Orta 4.3
  • CVE-2026-3225abone+≤ 4.3.2.8

    LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion

    Orta 4.3
  • CVE-2026-3226abone+≤ 4.3.2.8

    LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering

    Orta 4.3
  • CVE-2023-6223abone+≤ 4.2.5.7

    LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure

    Orta 4.3

Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS). Kayıt, wordpress.org'daki son sürümü (4.4.9.1) de etkilenen aralıkta gösteriyor.

← Dizine dön