Record summary

CVE-2024-1209 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 4.10.1affected

Proofs of concept

1

Repository PoCs

GitHubkarlemilnikka/CVE-2024-1209Repository PoCby karlemilnikkaStars: 2Not analyzed1 file

4.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMLearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignmentsCVSS 5.3

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

Impact

Unauthenticated attackers can access the LearnDash API to obtain uploaded student assignments and coursework that should be restricted to instructors and enrolled learners.

Remediation

Fixed in 4.10.2

Authorsritikchaddha
Template tagswpscancvecve2024wpwp-pluginwordpressexposurelearndashvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:learndash:learndash:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/sfwd-lms
FOFA: body=/wp-content/plugins/sfwd-lms
Google: inurl:"/wp-content/plugins/sfwd-lms"

Source: ProjectDiscovery

References

4