PatchSiren

thimpress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM thimpress CVE published 2026-07-17

CVE-2026-15094

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as c [truncated]

HIGH thimpress CVE published 2026-07-17

CVE-2026-13765

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the correct-answer markers, full option lists, explanations, and question content for any quiz question on the site — including question [truncated]

MEDIUM thimpress CVE published 2026-07-11

CVE-2026-11901

The WP Hotel Booking plugin for WordPress has a vulnerability in versions up to and including 2.3.1. This vulnerability is due to insufficient verification of data authenticity in the `web_hook_process_paypal_standard()` IPN handler. The handler selects its PayPal validation endpoint from an attacker-controlled parameter, allowing unauthenticated attackers to mark arbitrary hotel bookings as fully paid. T [truncated]

MEDIUM thimpress CVE published 2026-07-10

CVE-2026-11392

The WP Hotel Booking plugin for WordPress has a Reflected Cross-Site Scripting vulnerability. This vulnerability allows unauthenticated users to inject arbitrary web scripts via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1. The vulnerability has a CVSS score of 6.1 and a severity of MEDIUM. Users of the WP Hotel Booking plugin for WordPress should be awar [truncated]

MEDIUM thimpress CVE published 2026-06-06

CVE-2026-7566

The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact un [truncated]

MEDIUM thimpress CVE published 2026-04-08

CVE-2026-4333

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_courses shortcode in all versions up to and including 4.3.3. This is due to insufficient input sanitization and output escaping on the 'skin' shortcode attribute. The attribute value is used directly in an sprintf() call that generates HTML (class attribute an [truncated]