LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Minimum safe version
4.3.6
Update to 4.3.6 or later to address 74 fixable vulnerabilities
LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion
LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering
LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Answer Deletion
LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute
CVE-2025-14798
CVE-2025-14802
CVE-2025-13964
CVE-2025-66054
CVE-2025-13956
CVE-2025-14387
CVE-2025-67536
CVE-2025-11368
CVE-2025-11372
CVE-2024-13128
CVE-2025-22739
CVE-2024-13127
CVE-2025-24740
CVE-2024-13599
CVE-2024-10010
CVE-2024-9881
CVE-2024-11868
CVE-2024-8529
CVE-2024-8522
CVE-2024-7548
CVE-2024-39642
CVE-2024-39641
CVE-2024-6589
CVE-2024-6099
CVE-2024-6088
CVE-2024-5483
CVE-2024-4971
CVE-2024-4444
CVE-2024-4434
CVE-2024-4277
WordPress LearnPress Plugin <= 4.2.6.5 is vulnerable to Arbitrary File Upload
CVE-2024-3560
CVE-2024-1463
CVE-2024-1289
CVE-2024-2115
CVE-2023-5558
CVE-2023-6634
CVE-2023-6567
CVE-2023-6223
WordPress LearnPress Plugin < 4.2.5.4 is vulnerable to Cross Site Scripting (XSS)
LearnPress <= 4.2.5.3 - Reflected Cross-Site Scripting via add_internal_scripts_to_head
LearnPress <= 4.2.3 - Missing Authorization
CVE-2023-36515
CVE-2023-36516
CVE-2020-7917
LearnPress < 3.2.7.3 - CSRF & XSS
LearnPress < 4.1.6.7 - Reflected Cross-Site Scripting
CVE-2022-45808
CVE-2022-47615
CVE-2022-45820
LearnPress <= 3.2.7.2 - Reflected Cross-Site Scripting
LearnPress – WordPress LMS Plugin <= 3.2.7.2 - SQL Injection
LearnPress – WordPress LMS Plugin <= 4.1.6.5 - Reflected Cross-Site Scripting
LearnPress – WordPress LMS Plugin <= 4.1.6.7 - Reflected Cross-Site Scripting
CVE-2022-3360
WordPress LearnPress plugin <= 4.1.6.6 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress LearnPress plugin <= 3.2.6.8 - Authenticated Page Creation and Status Modification vulnerability
WordPress LearnPress plugin <= 3.2.7.2 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2022-0271
CVE-2018-16175
CVE-2018-16174
CVE-2018-16173
CVE-2020-7916
LearnPress <= 3.2.6.7 - SQL Injection
CVE-2020-11511
CVE-2021-24702
CVE-2021-39348
CVE-2021-24951
CVE-2022-0377