Showing 5 vulnerabilities on this page for LearnDash LMS

Signals CISA KEV Ransomware Nuclei
stellarwp vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter

The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existin

CWE-89Mar 24, 2026
CVSS6.5v3.1EPSS0.272%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

CWE-200Feb 5, 20241 related artifact
CVSS5.3v3.1EPSS5.29%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

CWE-200Feb 5, 20241 related artifact
CVSS5.3v3.1EPSS2.42%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

CWE-200Feb 5, 20241 related artifact
CVSS5.3v3.1EPSS2.03%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts.

CWE-639Jul 12, 2023
CVSS8.8v3.1EPSS2.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX