PT-2026-25505 · Thimpress · Thim Kit For Elementor – Pre-Built Templates & Widgets For Elementor

Youssef Elouaer

·

Published

2026-03-14

·

Updated

2026-03-16

·

CVE-2026-1870

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thim Kit for Elementor versions up to and including 1.3.7
Description The Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor plugin for WordPress is susceptible to unauthorized data access. A missing validation check on the thim-ekit/archive-course/get-courses API endpoint allows unauthenticated attackers to disclose private or draft LearnPress course content. This is achieved by manipulating the post status parameter within the params url payload.
Recommendations Versions up to and including 1.3.7 should be updated to a newer, fixed version when available. As a temporary workaround, restrict access to the thim-ekit/archive-course/get-courses API endpoint.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1870

Affected Products

Thim Kit For Elementor – Pre-Built Templates & Widgets For Elementor