{"schema_version":1,"title":"ThimPress vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in ThimPress: 1 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93899, was published on 25 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/thimpress","json_url":"https://junglewise.ai/threats/vendors/thimpress.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/thimpress","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":3,"all_time":15,"critical":0,"exploited":0,"last_7_days":1,"last_30_days":3,"last_90_days":8,"last_365_days":15},"latest":[{"cve":"CVE-2026-93899","cvss":6.5,"epss":0.0027,"slug":"cve-2026-93899-the-better-messages-chat-rooms-group-chat-private-messages-ai","title":"The Better Messages SQL Injection via group_id parameter","severity":"medium","exploited":false,"published_at":"2026-09-25T07:16:56.5+00:00","url":"https://junglewise.ai/threats/cve-2026-93899-the-better-messages-chat-rooms-group-chat-private-messages-ai"},{"cve":"CVE-2026-82024","cvss":5.4,"epss":0.0024,"slug":"cve-2026-82024-learnpress-wordpress-plugin-stored-cross-site-scripting-in-quiz","title":"LearnPress WordPress Plugin stored cross-site scripting in quiz answers","severity":"medium","exploited":false,"published_at":"2026-09-03T18:17:24.41+00:00","url":"https://junglewise.ai/threats/cve-2026-82024-learnpress-wordpress-plugin-stored-cross-site-scripting-in-quiz"},{"cve":"CVE-2026-82023","cvss":4.3,"epss":0.003,"slug":"cve-2026-82023-learnpress-broken-object-level-authorization-in-quiz-answer","title":"LearnPress broken object-level authorization in quiz answer insertion","severity":"medium","exploited":false,"published_at":"2026-09-03T18:17:24.26+00:00","url":"https://junglewise.ai/threats/cve-2026-82023-learnpress-broken-object-level-authorization-in-quiz-answer"},{"cve":"CVE-2026-57397","cvss":7.1,"slug":"cve-2026-57397-thimpress-coaching-unauthenticated-xss","title":"ThimPress Coaching unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-07-23T12:18:28.56+00:00","url":"https://junglewise.ai/threats/cve-2026-57397-thimpress-coaching-unauthenticated-xss"},{"cve":"CVE-2026-12970","cvss":7.1,"slug":"cve-2026-12970-learnpress-wordpress-plugin-reflected-xss-in-c-search-parameter","title":"LearnPress WordPress plugin reflected XSS in c_search parameter","severity":"info","exploited":false,"published_at":"2026-07-20T07:16:35.19+00:00","url":"https://junglewise.ai/threats/cve-2026-12970-learnpress-wordpress-plugin-reflected-xss-in-c-search-parameter"},{"cve":"CVE-2026-13765","cvss":7.5,"slug":"cve-2026-13765-thimpress-learnpress-sensitive-information-exposure-in-check","title":"ThimPress LearnPress sensitive information exposure in check_answer","severity":"high","exploited":false,"published_at":"2026-07-17T05:16:37.837+00:00","url":"https://junglewise.ai/threats/cve-2026-13765-thimpress-learnpress-sensitive-information-exposure-in-check"},{"cve":"CVE-2026-12732","cvss":6.4,"slug":"cve-2026-12732-thimpress-learnpress-stored-xss-in-class-wrapper-form-shortcode","title":"Thimpress LearnPress Stored XSS in class_wrapper_form shortcode","severity":"medium","exploited":false,"published_at":"2026-07-01T08:16:21.487+00:00","url":"https://junglewise.ai/threats/cve-2026-12732-thimpress-learnpress-stored-xss-in-class-wrapper-form-shortcode"},{"cve":"CVE-2026-11988","cvss":6.5,"slug":"cve-2026-11988-thimpress-learnpress-idor-in-userid-parameter","title":"ThimPress LearnPress IDOR in userId parameter","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:16.75+00:00","url":"https://junglewise.ai/threats/cve-2026-11988-thimpress-learnpress-idor-in-userid-parameter"},{"cve":"CVE-2026-8383","cvss":5.3,"epss":0.0025,"slug":"cve-2026-8383-learnpress-wordpress-plugin-missing-authorization-in-rest-api","title":"LearnPress WordPress plugin missing authorization in REST API","severity":"medium","exploited":false,"published_at":"2026-06-17T13:21:22.303+00:00","url":"https://junglewise.ai/threats/cve-2026-8383-learnpress-wordpress-plugin-missing-authorization-in-rest-api"},{"cve":"CVE-2026-8502","cvss":5.3,"slug":"cve-2026-8502-learnpress-wordpress-plugin-sensitive-information-exposure-in-rest","title":"LearnPress WordPress Plugin Sensitive Information Exposure in REST API","severity":"medium","exploited":false,"published_at":"2026-06-06T04:17:41.357+00:00","url":"https://junglewise.ai/threats/cve-2026-8502-learnpress-wordpress-plugin-sensitive-information-exposure-in-rest"},{"cve":"CVE-2025-53346","cvss":4.3,"slug":"cve-2025-53346-thimpress-thim-core-missing-authorization-in-access-control","title":"ThimPress Thim Core missing authorization in access control","severity":"medium","exploited":false,"published_at":"2026-06-02T10:16:20.223+00:00","url":"https://junglewise.ai/threats/cve-2025-53346-thimpress-thim-core-missing-authorization-in-access-control"},{"cve":"CVE-2025-53345","cvss":6.5,"slug":"cve-2025-53345-thimpress-thim-core-missing-authorization-leading-to-code","title":"ThimPress Thim Core missing authorization leading to code execution","severity":"medium","exploited":false,"published_at":"2026-06-02T10:16:20.107+00:00","url":"https://junglewise.ai/threats/cve-2025-53345-thimpress-thim-core-missing-authorization-leading-to-code"},{"cve":"CVE-2026-48865","cvss":7.1,"slug":"cve-2026-48865-thimpress-learnpress-reflected-xss","title":"ThimPress LearnPress reflected XSS","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:38.15+00:00","url":"https://junglewise.ai/threats/cve-2026-48865-thimpress-learnpress-reflected-xss"},{"cve":"CVE-2026-7648","cvss":4.3,"slug":"cve-2026-7648-learnpress-wordpress-plugin-payment-bypass-in-rest-api","title":"LearnPress WordPress Plugin payment bypass in REST API","severity":"medium","exploited":false,"published_at":"2026-05-14T05:16:46.08+00:00","url":"https://junglewise.ai/threats/cve-2026-7648-learnpress-wordpress-plugin-payment-bypass-in-rest-api"},{"cve":"CVE-2026-4333","cvss":6.4,"epss":0.0031,"slug":"cve-2026-4333-thimpress-learnpress-stored-xss-in-learn-press-courses-shortcode","title":"ThimPress LearnPress Stored XSS in learn_press_courses shortcode","severity":"medium","exploited":false,"published_at":"2026-04-08T05:16:06.683+00:00","url":"https://junglewise.ai/threats/cve-2026-4333-thimpress-learnpress-stored-xss-in-learn-press-courses-shortcode"}],"vendor":{"hub":true,"name":"ThimPress","slug":"thimpress","homepage":"https://thimpress.com/","description":"A developer of WordPress themes and plugins, primarily focused on education and learning management systems.","url":"https://junglewise.ai/threats/vendors/thimpress"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-13765","cvss":7.5,"slug":"cve-2026-13765-thimpress-learnpress-sensitive-information-exposure-in-check","title":"ThimPress LearnPress sensitive information exposure in check_answer","severity":"high","exploited":false,"published_at":"2026-07-17T05:16:37.837+00:00","url":"https://junglewise.ai/threats/cve-2026-13765-thimpress-learnpress-sensitive-information-exposure-in-check"},{"cve":"CVE-2026-57397","cvss":7.1,"slug":"cve-2026-57397-thimpress-coaching-unauthenticated-xss","title":"ThimPress Coaching unauthenticated XSS","severity":"high","exploited":false,"published_at":"2026-07-23T12:18:28.56+00:00","url":"https://junglewise.ai/threats/cve-2026-57397-thimpress-coaching-unauthenticated-xss"},{"cve":"CVE-2026-48865","cvss":7.1,"slug":"cve-2026-48865-thimpress-learnpress-reflected-xss","title":"ThimPress LearnPress reflected XSS","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:38.15+00:00","url":"https://junglewise.ai/threats/cve-2026-48865-thimpress-learnpress-reflected-xss"},{"cve":"CVE-2026-93899","cvss":6.5,"epss":0.0027,"slug":"cve-2026-93899-the-better-messages-chat-rooms-group-chat-private-messages-ai","title":"The Better Messages SQL Injection via group_id parameter","severity":"medium","exploited":false,"published_at":"2026-09-25T07:16:56.5+00:00","url":"https://junglewise.ai/threats/cve-2026-93899-the-better-messages-chat-rooms-group-chat-private-messages-ai"},{"cve":"CVE-2026-11988","cvss":6.5,"slug":"cve-2026-11988-thimpress-learnpress-idor-in-userid-parameter","title":"ThimPress LearnPress IDOR in userId parameter","severity":"medium","exploited":false,"published_at":"2026-07-01T05:16:16.75+00:00","url":"https://junglewise.ai/threats/cve-2026-11988-thimpress-learnpress-idor-in-userid-parameter"},{"cve":"CVE-2025-53345","cvss":6.5,"slug":"cve-2025-53345-thimpress-thim-core-missing-authorization-leading-to-code","title":"ThimPress Thim Core missing authorization leading to code execution","severity":"medium","exploited":false,"published_at":"2026-06-02T10:16:20.107+00:00","url":"https://junglewise.ai/threats/cve-2025-53345-thimpress-thim-core-missing-authorization-leading-to-code"},{"cve":"CVE-2026-4333","cvss":6.4,"epss":0.0031,"slug":"cve-2026-4333-thimpress-learnpress-stored-xss-in-learn-press-courses-shortcode","title":"ThimPress LearnPress Stored XSS in learn_press_courses shortcode","severity":"medium","exploited":false,"published_at":"2026-04-08T05:16:06.683+00:00","url":"https://junglewise.ai/threats/cve-2026-4333-thimpress-learnpress-stored-xss-in-learn-press-courses-shortcode"},{"cve":"CVE-2026-12732","cvss":6.4,"slug":"cve-2026-12732-thimpress-learnpress-stored-xss-in-class-wrapper-form-shortcode","title":"Thimpress LearnPress Stored XSS in class_wrapper_form shortcode","severity":"medium","exploited":false,"published_at":"2026-07-01T08:16:21.487+00:00","url":"https://junglewise.ai/threats/cve-2026-12732-thimpress-learnpress-stored-xss-in-class-wrapper-form-shortcode"},{"cve":"CVE-2026-82024","cvss":5.4,"epss":0.0024,"slug":"cve-2026-82024-learnpress-wordpress-plugin-stored-cross-site-scripting-in-quiz","title":"LearnPress WordPress Plugin stored cross-site scripting in quiz answers","severity":"medium","exploited":false,"published_at":"2026-09-03T18:17:24.41+00:00","url":"https://junglewise.ai/threats/cve-2026-82024-learnpress-wordpress-plugin-stored-cross-site-scripting-in-quiz"},{"cve":"CVE-2026-8383","cvss":5.3,"epss":0.0025,"slug":"cve-2026-8383-learnpress-wordpress-plugin-missing-authorization-in-rest-api","title":"LearnPress WordPress plugin missing authorization in REST API","severity":"medium","exploited":false,"published_at":"2026-06-17T13:21:22.303+00:00","url":"https://junglewise.ai/threats/cve-2026-8383-learnpress-wordpress-plugin-missing-authorization-in-rest-api"}],"generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[{"name":"ThimPress LearnPress","slug":"learnpress","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/learnpress"}]}