CVE-2020-11511: Thimpress Learnpress

High severity, CVSS 8.1. EPSS: 3.2% chance of exploitation in the next 30 days.

The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.

Affected products

  • Thimpress Learnpress: before 3.2.6.9 (fixed in 3.2.6.9)

Published 2021-07-30. Last modified 2026-06-17.