PT-2026-25505 · Thimpress · Thim Kit For Elementor – Pre-Built Templates & Widgets For Elementor
Youssef Elouaer
·
Published
2026-03-14
·
Updated
2026-03-16
·
CVE-2026-1870
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Thim Kit for Elementor versions up to and including 1.3.7
Description
The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is susceptible to unauthorized data access. A missing validation check on the
thim-ekit/archive-course/get-courses API endpoint allows unauthenticated attackers to disclose private or draft LearnPress course content. This is achieved by manipulating the post status parameter within the params url payload.Recommendations
Versions up to and including 1.3.7 should be updated to a newer, fixed version when available. As a temporary workaround, restrict access to the
thim-ekit/archive-course/get-courses API endpoint.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thim Kit For Elementor – Pre-Built Templates & Widgets For Elementor