LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
by ThimPress · Education
Also makes 19 other plugins · 185.1K+ installs across the portfolio →
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
90 health vs 66 average across 168 Education plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
82.6K
now · peak 147.4K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
27
releases in the last 12 months
2mo ago
latest release · v4.4.2
132
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 38% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “70K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-06-15 · 1,490 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ shaleneza2mo ago
I have been using LearnPress for years. I have noticed that support has very much improved. If you tried LP before and struggled, give it another chance. The plugin is really very good now and the support is excellent.
Read on wp.org ↗ - ★★★★★ sonicsha3mo ago
I totally recommend them. They smoothly helped me out in every way they can whenever I needed them.
Read on wp.org ↗ - ★★★★★ José Manuel4mo ago
Como es posible, que con la version 4.3.5, se rompa toda la base de datos? No distinque a los usuarios, se pierde la wishh-list, no salen los cursos en la portada…. un desastre. Como siga la cosa así, me busco otra LMS. This topic was modified 3 months ago by José Manuel.
Read on wp.org ↗ - ★★★★★ linternet65mo ago
Really nice, a joy to use.
Read on wp.org ↗ - ★★★★★ Dunos7mo ago
I’ve been using LearnPress for a while now and it does exactly what I need for building online courses. It’s easy to use, and the new AI feature is a great bonus. I really appreciate that the team keeps improving the plugin, and I’m excited to see what new features come in future updates. Definitely a 5-star plugin!
Read on wp.org ↗ - ★★★★★ Alex7mo ago
Easy and flexible plugin
Read on wp.org ↗ - ★★★★★ bakhtiyor1chi9mo ago
I recommend it for anyone who is planning to sell online courses or build platform for it. You can do it in your own language as well. The PlugIn has good interface, good speed and a wide range of features. They also offer paid theme but you get a long with free ones for the beginning. This topic was modified 7 months, 4 weeks ago by bakhtiyor1chi.
Read on wp.org ↗ - ★★★★★ robertodimaio10mo ago
The technical support hasn’t been the best so far, but it seems they’re improving, and considering the latest updates, I can express my full satisfaction. I hope this satisfaction continues over time. Good luck and thank to Brianvu-tp
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-22 Version 4.4.5 ~ Added: LearnPress Help Center in the admin menu. ~ Improved admin menu structure and how submenus are registered. ~ Improved reusable UI components: form filter, fullscreen, toggle enable. ~ Improved Students Enrolled 4.4.5
- 2026-08-03 Version 4.4.4 ~ Fixed: security. ~ Fixed: minor bugs. ~ Update some library to latest. 4.4.4
- 2026-07-26 Version 4.4.3 ~ Fixed: security. ~ Fixed: minor bugs. ~ Tweak: UI/UX statistic. 4.4.3
- 2026-07-11 Version 4.4.2 ~ Fixed: security. ~ Fixed: display Date time on Order. ~ Fixed: selected method payment on the checkout page. ~ Fixed: minor bug on Course Builder. ~ Unregister select2 library. ~ Added: feature Webhook. ~ MCP: added fu 4.4.2
- 2026-06-26 Version 4.4.1 ~ Fixed: security. ~ Fixed: minor bugs. 4.4.1
- 2026-06-16 Version 4.4.0 ~ Fixed: security. ~ Fixed: check permission create/edit course/lesson/quiz/question on Course Builder. ~ Fixed: editor edit question Fill In Blank. ~ Feature: refund order, support PayPal, option auto refund, refund req 4.4.0
Known vulnerabilities
via Wordfence Intelligence77 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-13 CVE-2026-12976 Exposure of Sensitive Information to an Unauthorized Actor Affects < 4.4.4 Patched in 4.4.4
- 2026-06-30 CVE-2026-12732 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.0 Patched in 4.4.1
- 2026-06-30 CVE-2026-11988 Authorization Bypass Through User-Controlled Key Affects <= 4.3.9.1 Patched in 4.4.0
- 2026-06-29 CVE-2026-12970 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.4.0 Patched in 4.4.1
- Medium · 6.1 LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.6 - Reflected Cross-Site Scripting ↗2026-06-01 CVE-2026-48865 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.3.6 Patched in 4.3.7
- 2026-05-13 CVE-2026-7648 Authorization Bypass Through User-Controlled Key Affects <= 4.3.5 Patched in 4.3.6
- Medium · 6.4 LearnPress <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'skin' Shortcode Attribute ↗2026-04-07 CVE-2026-4333 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.3.3 Patched in 4.3.4
- 2026-01-06 CVE-2025-14802 Authorization Bypass Through User-Controlled Key Affects <= 4.3.2.1 Patched in 4.3.2.2
- 2025-12-15 CVE-2025-14387 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.3.1 Patched in 4.3.2
- Medium · 5.3 LearnPress <= 4.2.9.4 - Missing Authorization ↗
- 2025-11-20 CVE-2025-11368 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.2.9.4 Patched in 4.3.0
- 2025-11-06 CVE-2025-67536 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.9.4 Patched in 4.3.0
- Medium · 5.3 LearnPress <= 4.2.7.5 - Missing Authorization ↗
- Medium · 4.4 LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2025-01-29 CVE-2024-13127 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.7.5 Patched in 4.2.7.5.1
- Medium · 4.4 LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (Admin+) Stored Cross-Site Scripting ↗2025-01-29 CVE-2024-13128 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.7.5 Patched in 4.2.7.5.1
- 2025-01-24 CVE-2024-13599 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.7.5 Patched in 4.2.7.5.1
- 2025-01-24 CVE-2025-24740 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 4.2.7.1 Patched in 4.2.7.2
- 2024-11-21 CVE-2024-10010 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.7.1 Patched in 4.2.7.2
- 2024-11-21 CVE-2024-9881 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.7.1 Patched in 4.2.7.2
- Critical · 10.0 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' ↗2024-09-11 CVE-2024-8529 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.2.7 Patched in 4.2.7.1
- Critical · 10.0 LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' ↗2024-09-11 CVE-2024-8522 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.2.7 Patched in 4.2.7.1
- 2024-08-07 CVE-2024-7548 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.2.6.9.3 Patched in 4.2.6.9.4
- Medium · 5.4 LearnPress <= 4.2.6.8.2 - Authenticated (Subscriber+) Insecure Direct Object Reference ↗2024-08-01 CVE-2024-39642 Authorization Bypass Through User-Controlled Key Affects <= 4.2.6.8.2 Patched in 4.2.6.9
- 2024-07-24 CVE-2024-6589 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 4.2.6.8.2 Patched in 4.2.6.9
- Medium · 5.3 LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API ↗2024-06-04 CVE-2024-5483 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 4.2.6.8 Patched in 4.2.6.8.1
- 2024-05-21 CVE-2024-4971 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.6.6 Patched in 4.2.6.7
- 2024-05-09 CVE-2024-4277 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.6.5 Patched in 4.2.6.6
- Critical · 9.8 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection ↗2024-05-09 CVE-2024-4434 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.2.6.5 Patched in 4.2.6.6
- High · 8.8 LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload ↗2024-05-09 CVE-2024-4397 Unrestricted Upload of File with Dangerous Type Affects <= 4.2.6.5 Patched in 4.2.6.6
- Medium · 6.4 LearnPress – WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-04-18 CVE-2024-3560 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.6.4 Patched in 4.2.6.5
- 2024-04-04 CVE-2024-1463 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.2.6.3 Patched in 4.2.6.4
- High · 8.1 LearnPress <= 4.2.5.7 - Command Injection ↗2024-01-03 CVE-2023-6634 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') Affects <= 4.2.5.7 Patched in 4.2.5.8
- 2024-01-02 CVE-2023-6223 Authorization Bypass Through User-Controlled Key Affects <= 4.2.5.7 Patched in 4.2.5.8
- 2024-01-02 CVE-2023-6567 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.2.5.7 Patched in 4.2.5.8
- Medium · 6.1 LearnPress <= 4.2.5.3 - Reflected Cross-Site Scripting via add_internal_scripts_to_head ↗2023-11-07 CVE-2023-5558 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.2.5.4 Patched in 4.2.5.4
- Medium · 5.4 LearnPress <= 4.2.3 - Missing Authorization ↗2023-07-06 Missing Authorization Affects < 4.2.3.1 Patched in 4.2.3.1
- Medium · 5.4 LearnPress <= 4.2.3 - Missing Authorization ↗
- Critical · 9.8 LearnPress <= 4.1.7.3.2 - Unauthenticated SQL Injection ↗2023-01-20 CVE-2022-45808 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.1.7.3.2 Patched in 4.2.0
- 2023-01-20 CVE-2022-47615 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 4.1.7.3.2 Patched in 4.2.0
- 2022-12-20 CVE-2022-45820 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.1.7.3.2 Patched in 4.2.0
- 2022-07-05 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.6.7 Patched in 4.1.6.8
- 2022-06-14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.6.5 Patched in 4.1.6.6
- 2022-03-16 CVE-2022-0271 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 4.1.6 Patched in 4.1.6
- Medium · 4.3 LearnPress <= 4.1.4.1 - Arbitrary Image Renaming ↗
- Critical · 9.8 LearnPress <= 4.1.3 - Authenticated SQL Injection ↗2021-11-09 CVE-2021-24951 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.1.4 Patched in 4.1.4
- 2021-10-18 CVE-2021-39348 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.3.1 Patched in 4.1.3.2
- 2021-09-20 CVE-2021-24702 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.3 Patched in 4.1.3.1
- High · 8.8 LearnPress <= 3.2.6.7 - SQL Injection ↗2021-07-19 CVE-2020-6010 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.2.6.7 Patched in 3.2.6.8
- 2020-10-05 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.2.7.2 Patched in 3.2.7.3
- 2020-09-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.7.3 Patched in 3.2.7.3
- 2018-11-09 CVE-2018-16175 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.0.12 Patched in 3.1.0
- Medium · 6.1 LearnPress <= 3.0.12 - Open Redirect ↗2018-11-09 CVE-2018-16174 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 3.0.12 Patched in 3.1.0
- Medium · 6.1 LearnPress <= 3.0.12 - Cross-Site Scripting ↗2018-11-09 CVE-2018-16173 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.12 Patched in 3.1.0
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 128 languages, 3 at 90% or more
Plus 104 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-05-15 80K+ → 70K+ down after 223 days in tier
- 2025-10-04 90K+ → 80K+ down after 818 days in tier
- 2023-07-09 100K+ → 90K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Tutor LMS – eLearning and online course solution 100K+ installs · 4.4★ · 5 shared tags B -
MasterStudy LMS WordPress Plugin – for Online Courses and Education 10K+ installs · 4.5★ · 5 shared tags A -
StepUp LMS — installs · 3.6★ · 5 shared tags B -
LearnPress – Course Wishlist 20K+ installs · 3.9★ · 4 shared tags B -
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes 10K+ installs · 4.8★ · 4 shared tags A
-
LearnPress – Prerequisites Courses 6K+ installs · 4.0★ · 4 shared tags B
Embed this report card
Drop a live Pulse card for LearnPress – WordPress LMS Plugin for Create and Sell Online Courses into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/learnpress" width="480" height="300" style="border:0" loading="lazy" title="LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — Plugin Pulse"></iframe> LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 70K+ active installs, 4.3★ (596 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/learnpress