Record summary

CVE-2024-1210 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 15, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 4.10.1affected

Proofs of concept

1

Repository PoCs

GitHubkarlemilnikka/CVE-2024-1208-and-CVE-2024-1210Repository PoCby karlemilnikkaStars: 3Not analyzed1 file

4.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMLearnDash LMS < 4.10.2 - Sensitive Information ExposureCVSS 5.3

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

Impact

Unauthenticated attackers can access the LearnDash API to obtain sensitive quiz materials, questions, and course content that should be restricted to enrolled learners.

Remediation

Fixed in 4.10.2

Authorsritikchaddha
Template tagswpscancvecve2024wpwp-pluginwordpressexposurelearndashvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:learndash:learndash:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/sfwd-lms
FOFA: body=/wp-content/plugins/sfwd-lms
Google: inurl:"/wp-content/plugins/sfwd-lms"

Source: ProjectDiscovery

References

4