Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-1208. PoCs published by karlemilnikka, Cappricio-Securities. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-1208 and CVE-2024-1210, which involve sensitive information exposure via API in LearnDash. It explains the vulnerability, affected endpoints, and the patch timeline.
Description
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
Exploits (2)
This repository provides a detailed technical analysis of CVE-2024-1208 and CVE-2024-1210, which involve sensitive information exposure via API in LearnDash. It explains the vulnerability, affected endpoints, and the patch timeline.
This repository contains a Python-based scanner for detecting CVE-2024-1208 by checking for specific response patterns in HTTP endpoints. It includes features like Telegram notifications and bulk URL scanning but does not include exploit code.
Nuclei Templates (1)
http.html:/wp-content/plugins/sfwd-lms
body=/wp-content/plugins/sfwd-lms
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N