LearnDash Vulnerabilities and Affected Products
Vulnerabilities associated with learndash.
Products
Clear product- learndash2 vulnerabilities
- LearnDash LMS2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-28777HIGH | WordPress LearnDash LMS Plugin <= 4.5.3 is vulnerable to SQL InjectionImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3. CWE-89Oct 31, 2023 | CVSS8.5v3.1 | EPSS0.684% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3105HIGH | LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password ChangeThe LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts. CWE-639Jul 12, 2023 | CVSS8.8v3.1 | EPSS2.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |