Is "LearnPress – WordPress LMS Plugin" safe?
WordPress Plugin security and safety information.
Rating: Good (current version safe)
Recommendations
LearnPress – WordPress LMS Plugin: Plugin Details
| Type: | Plugin |
| Author: | ThimPress |
| URL: | https://wordpress.org/plugins/learnpress/ |
| Latest Version: | 4.2.7.9 |
LearnPress – WordPress LMS Plugin: Security Information
| Insecure versions: | Up To 4.2.7.5 |
| Known since: | 2025-01-29 14:00:35 |
| Insecure versions: | Up To 4.2.7.5 |
| Known since: | 2025-01-29 14:00:34 |
| Insecure versions: | Up To 4.2.7.1 |
| Known since: | 2025-01-29 14:00:34 |
| Insecure versions: | Up To 4.2.7.5 |
| Known since: | 2025-01-25 02:00:38 |
| Insecure versions: | Up To 4.2.7.3 |
| Known since: | 2024-12-10 00:31:29 |
| Insecure versions: | Up To 4.2.7.1 |
| Known since: | 2024-11-21 14:32:01 |
| Insecure versions: | Up To 4.2.7.1 |
| Known since: | 2024-11-21 14:32:00 |
| Insecure versions: | Up To 4.2.7 |
| Known since: | 2024-09-12 02:00:26 |
| Insecure versions: | Up To 4.2.7 |
| Known since: | 2024-09-12 02:00:25 |
| Insecure versions: | Up To 4.2.6.9.3 |
| Known since: | 2024-08-08 02:01:18 |
| Insecure versions: | Up To 4.2.6.8.2 |
| Known since: | 2024-08-07 17:31:40 |
| Insecure versions: | Up To 4.2.6.8.2 |
| Known since: | 2024-08-07 17:31:39 |
| Insecure versions: | Up To 4.2.6.8.2 |
| Known since: | 2024-07-25 02:00:21 |
| Insecure versions: | Up To 4.2.6.8.1 |
| Known since: | 2024-07-02 21:21:24 |
| Insecure versions: | Up To 4.2.6.8.1 |
| Known since: | 2024-07-02 21:21:24 |
| Insecure versions: | Up To 4.2.6.8 |
| Known since: | 2024-06-05 02:01:21 |
| Insecure versions: | Up To 4.2.6.6 |
| Known since: | 2024-06-04 14:30:29 |
| Insecure versions: | Up To 4.2.6.5 |
| Known since: | 2024-05-11 02:01:14 |
| Insecure versions: | Up To 4.2.6.5 |
| Known since: | 2024-05-09 21:30:40 |
| Insecure versions: | Up To 4.2.6.5 |
| Known since: | 2024-05-09 21:30:40 |
| Insecure versions: | Up To 4.2.6.5 |
| Known since: | 2024-05-09 20:30:34 |
| Insecure versions: | Up To 4.2.6.4 |
| Known since: | 2024-04-18 14:30:45 |
| Insecure versions: | Up To 4.0.0 |
| Known since: | 2024-04-05 02:00:39 |
| Insecure versions: | Up To 4.2.6.3 |
| Known since: | 2024-04-05 02:00:38 |
| Insecure versions: | Up To 4.2.6.3 |
| Known since: | 2024-04-04 19:00:28 |
| Insecure versions: | Up To 4.2.5.7 |
| Known since: | 2024-04-04 18:30:47 |
| Insecure versions: | Up To 4.2.5.7 |
| Known since: | 2024-01-04 08:37:42 |
| Insecure versions: | Up To 4.2.5.7 |
| Known since: | 2024-01-04 08:37:41 |
| Insecure versions: | Up To 4.2.5.4 |
| Known since: | 2023-11-18 02:00:14 |
| Insecure versions: | Up To 4.1.7.3.2 |
| Known since: | 2023-01-25 02:00:19 |
| Insecure versions: | Up To 4.1.7.3.2 |
| Known since: | 2023-01-25 02:00:18 |
| Insecure versions: | Up To 4.1.7.3.2 |
| Known since: | 2023-01-25 02:00:17 |
| Insecure versions: | Up To 4.1.7.1 |
| Known since: | 2022-10-06 11:20:07 |
| Insecure versions: | Up To 4.1.6.6 |
| Known since: | 2022-06-23 11:42:11 |
| Insecure versions: | Up To 4.1.5 |
| Known since: | 2022-03-16 10:39:41 |
| Insecure versions: | Up To 4.1.4.1 |
| Known since: | 2022-01-26 15:26:49 |
| Insecure versions: | Up To 4.1.4-beta-2 |
| Known since: | 2021-11-11 16:52:44 |
| Insecure versions: | Up To 4.1.3.1 |
| Known since: | 2021-10-19 19:14:53 |
| Insecure versions: | Up To 4.1.3 |
| Known since: | 2021-09-21 10:34:25 |
| Insecure versions: | Up To 3.2.6.9 |
| Known since: | 2020-09-10 20:36:48 |
| Description: | Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack. |
| Insecure versions: | Up To 3.2.6.7 |
| Known since: | 2020-05-01 00:05:41 |
| Description: | This could allow a low privilege user, to perform a time based SQL Injection attack and retrieve data from the DB, such as hashed passwords. |
| Insecure versions: | Up To 3.2.6.7 |
| Known since: | 2020-04-28 23:26:15 |
| Description: | Allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter. |
| Insecure versions: | Up To 3.2.6.7 |
| Known since: | 2020-04-28 23:24:28 |
| Description: | The LearnPress plugin allows authenticated remote attackers with minimal permissions to create pages with arbitrary titles, or modify the publication status of any existing page, via the learnpress_create_page or learnpress_update_order_status AJAX actions. |
| Insecure versions: | Up To 3.2.6.7 |
| Known since: | 2020-04-28 23:24:28 |
| Description: | The LearnPress plugin allows authenticated remote attackers with minimal permissions to create pages with arbitrary titles, or modify the publication status of any existing page, via the learnpress_create_page or learnpress_update_order_status AJAX actions. |
LearnPress – WordPress LMS Plugin: Safety Recommendations
We have rated LearnPress – WordPress LMS Plugin as Good (current version safe) which means that we have found vulnerabilities in older versions.
We recommend that you only use the latest version of LearnPress – WordPress LMS Plugin.
LearnPress – WordPress LMS Plugin: Staying Up-to-date
Make sure your installation of LearnPress – WordPress LMS Plugin is safe with the following free Jetpack services for WordPress sites:
- Updates & Management
Turn on auto-updates for LearnPress – WordPress LMS Plugin or manage in bulk. - Prevent Infiltrations
Automatic protection against brute force attacks and secure sign on.
LearnPress – WordPress LMS Plugin: Keeping Safe
If you're running a business, ecommerce, news, or other critical website, Jetpack also provides additional indispensable services:
- Automated Backups
Full backup of your entire site with unlimited storage space. - Restores & Migrations
Restore or migrate your site from a backup with one click. - Security Scanning
Regular, automated scans of your site for malware, threats, and hacks. - Expert Support
Fast, priority support for any WordPress security issue.
About this information
This WordPress security information is part of our security library and is brought to you by Jetpack as part of our committment to a safer WordPress experience.
If you have any questions, please do not hesitate to contact us.