Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 73 vulnerability records associated with LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, published between 2018 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

73Total records
9Critical
14High
50Medium
0Low
0Informational
73Patched records
0Currently marked unpatched
2018-11-09First disclosure
2026-07-16Latest disclosure
68 of 73CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201833 records
202055 records
202144 records
202266 records
202366 records
20242424 records
20251111 records
20261414 records

Severity Breakdown

SeverityRecordsShare
Critical912.3%
High1419.2%
Medium5068.5%

Vulnerability-Type Breakdown

Cross-Site Scripting

23 records31.5%

First: 2018. Latest: 2026.

Missing Authorization

21 records28.8%

First: 2023. Latest: 2026.

SQL Injection

11 records15.1%

First: 2018. Latest: 2024.

Other

7 records9.6%

First: 2018. Latest: 2025.

Privilege Escalation

4 records5.5%

First: 2020. Latest: 2024.

Path Traversal

2 records2.7%

First: 2022. Latest: 2023.

CSRF

2 records2.7%

First: 2024. Latest: 2024.

Information Disclosure

2 records2.7%

First: 2024. Latest: 2025.

Arbitrary File Upload

1 record1.4%

First: 2024. Latest: 2024.

Patch Status

Patched
73
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.4.2
  • 4.4.1
  • 4.4.0
  • 4.3.7
  • 4.3.6
  • 4.3.3
  • 4.3.4
  • 4.3.2.5
  • 4.3.2.2
  • 4.3.2.1
  • 4.3.2
  • 4.3.0
  • 4.2.9.4
  • 4.2.7.6
  • 4.2.7.5.1
  • 4.2.7.4
  • 4.2.7.2
  • 4.2.7.1
  • 4.2.6.9.4
  • 4.2.6.9
  • 4.2.6.8.2
  • 4.2.6.8.1
  • 4.2.6.7
  • 4.2.6.6
  • 4.2.6.5
  • 4.0.1
  • 4.2.6.4
  • 4.2.5.8
  • 4.2.5.4
  • 4.2.3.1
  • 4.2.0
  • 4.1.7.2
  • 4.1.6.8
  • 4.1.6.6
  • 4.1.6
  • 4.1.5
  • 4.1.4
  • 4.1.3.2
  • 4.1.3.1
  • 3.2.6.8
  • 3.2.7.3
  • 3.2.6.9
  • 3.1.0

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
[*, 4.2.3.1)LearnPress <= 4.2.3 - Missing AuthorizationJuly 6, 20234.2.3.1Medium
*-4.2.3LearnPress <= 4.2.3 - Missing Authorization to Information ExposureJuly 4, 20234.2.3.1High
*-4.2.3LearnPress <= 4.2.3 - Missing AuthorizationJuly 4, 20234.2.3.1Medium
*-4.1.7.3.2LearnPress <= 4.1.7.3.2 - Unauthenticated Local File InclusionJanuary 20, 20234.2.0Critical
*-4.1.7.3.2LearnPress <= 4.1.7.3.2 - Unauthenticated SQL InjectionJanuary 20, 20234.2.0Critical
*-4.1.7.3.2LearnPress <= 4.1.7.3.2 - Authenticated (Subscriber+) SQL InjectionDecember 20, 20224.2.0High
*-4.1.7.1LearnPress <= 4.1.7.1 - Unauthenticated PHP Object InjectionOctober 3, 20224.1.7.2Critical
*-4.1.6.7LearnPress – WordPress LMS Plugin <= 4.1.6.7 - Reflected Cross-Site ScriptingJuly 5, 20224.1.6.8Medium
*-4.1.6.5LearnPress – WordPress LMS Plugin <= 4.1.6.5 - Reflected Cross-Site ScriptingJune 14, 20224.1.6.6Medium
[*, 4.1.6)LearnPress <= 4.1.5 - Reflected Cross-Site ScriptingMarch 16, 20224.1.6Medium
*-4.1.4.1LearnPress <= 4.1.4.1 - Arbitrary Image RenamingJanuary 26, 20224.1.5Medium
[*, 4.1.4)LearnPress <= 4.1.3 - Authenticated SQL InjectionNovember 9, 20214.1.4Critical
*-4.1.3.1LearnPress <= 4.1.3.1 - Stored Cross-Site Scripting via $custom_profileOctober 18, 20214.1.3.2Medium
*-4.1.3LearnPress <= 4.1.3 - Authenticated Stored Cross-Site ScriptingSeptember 20, 20214.1.3.1Medium
*-3.2.6.7LearnPress <= 3.2.6.7 - SQL InjectionJuly 19, 20213.2.6.8High
*-3.2.7.2LearnPress – WordPress LMS Plugin <= 3.2.7.2 - SQL InjectionOctober 5, 20203.2.7.3High
[*, 3.2.7.3)LearnPress <= 3.2.7.2 - Reflected Cross-Site ScriptingSeptember 8, 20203.2.7.3Medium
*-3.2.6.8LearnPress <= 3.2.6.8 - Privilege Escalation via accept-to-be-teacher action parameterApril 20, 20203.2.6.9High
*-3.2.6.8LearnPress <= 3.2.6.8 - Authenticated Page Creation and Status ModificationApril 19, 20203.2.6.9High
*-3.2.6.6LearnPress <= 3.2.6.6 - Privilege EscalationMarch 16, 20203.2.6.8High
*-3.0.12LearnPress <= 3.0.12 - Cross-Site ScriptingNovember 9, 20183.1.0Medium
*-3.0.12LearnPress <= 3.0.12 - Open RedirectNovember 9, 20183.1.0Medium
*-3.0.12LearnPress <= 3.0.12 - Authenticated SQL InjectionNovember 9, 20183.1.0High

Selected source records

Latest Records

HighCVE-2026-13765

LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints

Published: July 16, 2026

Affected versions
*-4.4.1
Patched versions
4.4.2
Original Wordfence record
MediumCVE-2026-12732

LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute

Published: June 30, 2026

Affected versions
*-4.4.0
Patched versions
4.4.1
Original Wordfence record
MediumCVE-2026-11988

LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter

Published: June 30, 2026

Affected versions
*-4.3.9.1
Patched versions
4.4.0
Original Wordfence record
MediumCVE-2026-12970

LearnPress <= 4.4.0 - Reflected Cross-Site Scripting

Published: June 29, 2026

Affected versions
*-4.4.0
Patched versions
4.4.1
Original Wordfence record
MediumCVE-2026-8502

LearnPress <= 4.3.6 - Unauthenticated Sensitive Information Exposure via 'c_status' and 'return_type' Parameters

Published: June 5, 2026

Affected versions
*-4.3.6
Patched versions
4.3.7
Original Wordfence record
MediumCVE-2026-48865

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 - Reflected Cross-Site Scripting

Published: June 1, 2026

Affected versions
*-4.3.6
Patched versions
4.3.7
Original Wordfence record
MediumCVE-2026-7648

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter

Published: May 13, 2026

Affected versions
*-4.3.5
Patched versions
4.3.6
Original Wordfence record
CriticalCVE-2026-4365

LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion

Published: April 13, 2026

Affected versions
*-4.3.2.8
Patched versions
4.3.3
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-8529

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'

Published: September 11, 2024

Affected versions
*-4.2.7
Patched versions
4.2.7.1
Original Wordfence record
CriticalCVE-2024-8522

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'

Published: September 11, 2024

Affected versions
*-4.2.7
Patched versions
4.2.7.1
Original Wordfence record
CriticalCVE-2024-4434

LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection

Published: May 9, 2024

Affected versions
*-4.2.6.5
Patched versions
4.2.6.6
Original Wordfence record
CriticalCVE-2021-24951

LearnPress <= 4.1.3 - Authenticated SQL Injection

Published: November 9, 2021

Affected versions
[*, 4.1.4)
Patched versions
4.1.4
Original Wordfence record
CriticalCVE-2023-6567

LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by

Published: January 2, 2024

Affected versions
*-4.2.5.7
Patched versions
4.2.5.8
Original Wordfence record
CriticalCVE-2022-45808

LearnPress <= 4.1.7.3.2 - Unauthenticated SQL Injection

Published: January 20, 2023

Affected versions
*-4.1.7.3.2
Patched versions
4.2.0
Original Wordfence record
CriticalCVE-2022-47615

LearnPress <= 4.1.7.3.2 - Unauthenticated Local File Inclusion

Published: January 20, 2023

Affected versions
*-4.1.7.3.2
Patched versions
4.2.0
Original Wordfence record
CriticalCVE-2022-3360

LearnPress <= 4.1.7.1 - Unauthenticated PHP Object Injection

Published: October 3, 2022

Affected versions
*-4.1.7.1
Patched versions
4.1.7.2
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory