Thimpress Learnpress Backup Migration Tool vulnerabilities
2 known vulnerabilities affecting thimpress/learnpress_backup_migration_tool.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-1787MEDIUMCVSS 4.8≤ 4.1.02026-02-21
CVE-2026-1787 [MEDIUM] CWE-862 CVE-2026-1787: The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable
The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to delete course that have been migrated from Tutor
cvelistv5nvd
CVE-2024-9609MEDIUMCVSS 6.1≤ 4.0.42024-11-15
CVE-2024-9609 [MEDIUM] CWE-79 CVE-2024-9609: The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable
The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar
cvelistv5nvd