PT-2026-25505 · Thimpress · Thim Kit For Elementor – Pre-Built Templates & Widgets For Elementor
Youssef Elouaer
·
Publicado
2026-03-14
·
Atualizado
2026-03-16
·
CVE-2026-1870
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Thim Kit for Elementor versions up to and including 1.3.7
Description
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is susceptible to unauthorized data access. A missing validation check on the
thim-ekit/archive-course/get-courses API endpoint allows unauthenticated attackers to disclose private or draft LearnPress course content. This is achieved by manipulating the post status parameter within the params url payload.Recommendations
Versions up to and including 1.3.7 should be updated to a newer, fixed version when available. As a temporary workaround, restrict access to the
thim-ekit/archive-course/get-courses API endpoint.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Thim Kit For Elementor – Pre-Built Templates & Widgets For Elementor