CVE-2024-1208

MEDIUM NUCLEI

LearnDash LMS <4.10.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-1208. PoCs published by karlemilnikka, Cappricio-Securities. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-1208 and CVE-2024-1210, which involve sensitive information exposure via API in LearnDash. It explains the vulnerability, affected endpoints, and the patch timeline.

Description

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

Exploits (2)

nomisec WRITEUP 3 stars
by karlemilnikka · poc
https://github.com/karlemilnikka/CVE-2024-1208-and-CVE-2024-1210

This repository provides a detailed technical analysis of CVE-2024-1208 and CVE-2024-1210, which involve sensitive information exposure via API in LearnDash. It explains the vulnerability, affected endpoints, and the patch timeline.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: LearnDash (sfwd-lms) <= 4.10.2
No auth needed
Prerequisites: Access to the target WordPress site with LearnDash plugin installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER 1 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2024-1208

This repository contains a Python-based scanner for detecting CVE-2024-1208 by checking for specific response patterns in HTTP endpoints. It includes features like Telegram notifications and bulk URL scanning but does not include exploit code.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Unknown (scanner checks for specific response patterns)
No auth needed
Prerequisites: Python 3 · pip · network connectivity
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

LearnDash LMS < 4.10.3 - Sensitive Information Exposure
MEDIUMVERIFIEDby ritikchaddha
Shodan: http.html:/wp-content/plugins/sfwd-lms
FOFA: body=/wp-content/plugins/sfwd-lms

Scores

CVSS v3 5.3
EPSS 0.0529
EPSS Percentile 91.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
learndash/learndash < 4.10.3
StellarWP/LearnDash LMS < 4.10.2
Published Feb 05, 2024
Tracked Since Feb 18, 2026