stellarwp Vulnerabilities and Affected Products
Vulnerabilities associated with LearnDash LMS.
Products
Clear product- GiveWP – Donation Plugin and Fundraising Platform31 vulnerabilities
- Kadence Blocks — Page Builder Toolkit for Gutenberg Editor29 vulnerabilities
- The Events Calendar19 vulnerabilities
- GiveWP10 vulnerabilities
- Membership Plugin – Restrict Content7 vulnerabilities
- Event Tickets and Registration6 vulnerabilities
- LearnDash LMS5 vulnerabilities
- Bookit — Booking & Appointment Calendar3 vulnerabilities
- Event Tickets3 vulnerabilities
- Gutenberg Blocks by Kadence Blocks3 vulnerabilities
- Kadence WooCommerce Email Designer3 vulnerabilities
- WPComplete3 vulnerabilities
- Restrict Content2 vulnerabilities
- Give – Divi Donation Modules1 vulnerability
- Image Widget1 vulnerability
- iThemes Sync1 vulnerability
- LearnDash LMS – Reports1 vulnerability
- Membership Plugin – Kadence Memberships1 vulnerability
- the_events_calendar1 vulnerability
- Virtue1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-3079MEDIUM | LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' ParameterThe LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existin… CWE-89Mar 24, 2026 | CVSS6.5v3.1 | EPSS0.272% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1208MEDIUM | LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via APIThe LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions. | CVSS5.3v3.1 | EPSS5.29% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-1209MEDIUM | LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignmentsThe LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads. | CVSS5.3v3.1 | EPSS2.42% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-1210MEDIUM | LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via APIThe LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes. | CVSS5.3v3.1 | EPSS2.03% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-3105HIGH | LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password ChangeThe LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts. CWE-639Jul 12, 2023 | CVSS8.8v3.1 | EPSS2.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |