CVE-2024-4444: Thimpress Learnpress

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

Affected products

  • Thimpress Learnpress: before 4.2.6.6 (fixed in 4.2.6.6)

Published 2024-05-14. Last modified 2026-06-17.