PT-2024-28578 · Thimpress · Learnpress

Rafie Muhammad

·

Published

2024-08-26

·

Updated

2024-09-18

·

CVE-2024-39641

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThimPress LearnPress versions through 4.2.6.8.2
Description The issue is a Cross-Site Request Forgery (CSRF) vulnerability. It affects the WordPress LearnPress Plugin, allowing for potential exploitation. To remediate the issue, an upgrade to version 4.2.6.9 is recommended.
Recommendations For versions through 4.2.6.8.2, upgrade to version 4.2.6.9 to resolve the issue. As a temporary workaround, consider implementing additional security measures to minimize the risk of CSRF exploitation until the upgrade can be applied.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-39641

Affected Products

Learnpress