LearnDash LMS - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter vulnerability
high
Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter vulnerability
- CVSS:
- 8.5
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3.1
- Disclosed:
- Mar 24, 2026
LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter
medium
The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...
- CVSS:
- 6.5
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3.1
- Disclosed:
- Mar 23, 2026
CVE-2026-3079 on NVD →
LearnDash LMS [sfwd-lms] < 4.20.0.3
unknown
[en] Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1.
- Affected:
- up to 4.20.0.3
- Fixed in:
- 4.20.0.3
- Disclosed:
- Jan 27, 2025
CVE-2025-24662 on NVD →
LearnDash LMS <= 4.20.0.1 - Missing Authorization
medium
The LearnDash LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.20.0.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.20.0.1
- Fixed in:
- 4.20.0.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24662 on NVD →
LearnDash LMS [sfwd-lms] < 4.10.3
unknown
[en] The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
- Affected:
- up to 4.10.3
- Fixed in:
- 4.10.3
- Disclosed:
- Feb 5, 2024
CVE-2024-1208 on NVD →
LearnDash LMS [sfwd-lms] < 4.10.2
unknown
[en] The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
- Affected:
- up to 4.10.2
- Fixed in:
- 4.10.2
- Disclosed:
- Feb 5, 2024
CVE-2024-1209 on NVD →
LearnDash LMS [sfwd-lms] < 4.10.2
unknown
[en] The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.
- Affected:
- up to 4.10.2
- Fixed in:
- 4.10.2
- Disclosed:
- Feb 5, 2024
CVE-2024-1210 on NVD →
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API
medium
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.
- CVSS:
- 5.3
- Affected:
- up to 4.10.1
- Fixed in:
- 4.10.2
- Disclosed:
- Feb 2, 2024
CVE-2024-1210 on NVD →
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments
medium
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
- CVSS:
- 5.3
- Affected:
- up to 4.10.1
- Fixed in:
- 4.10.2
- Disclosed:
- Feb 2, 2024
CVE-2024-1209 on NVD →
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
medium
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
- CVSS:
- 5.3
- Affected:
- up to 4.10.2
- Fixed in:
- 4.10.3
- Disclosed:
- Feb 2, 2024
CVE-2024-1208 on NVD →
LearnDash LMS [sfwd-lms] < 4.10.3
unknown
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
- Affected:
- up to 4.10.3
- Fixed in:
- 4.10.3
- Disclosed:
- Feb 2, 2024
LearnDash LMS [sfwd-lms] < 4.10.2
unknown
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
- Affected:
- up to 4.10.2
- Fixed in:
- 4.10.2
- Disclosed:
- Feb 2, 2024
LearnDash LMS [sfwd-lms] < 4.10.2
unknown
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.
- Affected:
- up to 4.10.2
- Fixed in:
- 4.10.2
- Disclosed:
- Feb 2, 2024
LearnDash LMS [sfwd-lms] < 4.5.3.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3.
- Affected:
- up to 4.5.3.1
- Fixed in:
- 4.5.3.1
- Disclosed:
- Oct 31, 2023
CVE-2023-28777 on NVD →
LearnDash LMS [sfwd-lms] < 4.6.0.1
unknown
[en] The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with e...
- Affected:
- up to 4.6.0.1
- Fixed in:
- 4.6.0.1
- Disclosed:
- Jul 12, 2023
CVE-2023-3105 on NVD →
LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change
high
The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existi...
- CVSS:
- 8.8
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.0.1
- Disclosed:
- Jun 27, 2023
CVE-2023-3105 on NVD →
LearnDash LMS <= 4.5.3 - Authenticated (Contributor+) SQL Injection
high
The LearnDash LMS plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 8.8
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.3.1
- Disclosed:
- May 22, 2023
CVE-2023-28777 on NVD →
LearnDash LMS [sfwd-lms] < 2.5.4
unknown
[en] The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Nov 1, 2021
CVE-2018-25019 on NVD →
LearnDash <= 3.1.5 - Unauthenticated SQL Injection
critical
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
- CVSS:
- 9.8
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.6
- Disclosed:
- Apr 1, 2020
CVE-2020-6009 on NVD →
LearnDash LMS [sfwd-lms] < 3.1.6
unknown
[en] LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
- Affected:
- up to 3.1.6
- Fixed in:
- 3.1.6
- Disclosed:
- Apr 1, 2020
CVE-2020-6009 on NVD →
LearnDash LMS [sfwd-lms] < 3.1.2
unknown
[en] The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jan 16, 2020
CVE-2020-7108 on NVD →
LearnDash 3.0.0-3.1.1 - Reflected Cross Site Scripting issue on the [ld_profile] search field
medium
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
- CVSS:
- 6.1
- Affected:
- 3.0.0 – 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Jan 15, 2020
CVE-2020-7108 on NVD →
LearnDash LMS <= 2.5.3 - Arbitrary File Upload
high
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
- CVSS:
- 7.5
- Affected:
- up to 2.5.4
- Fixed in:
- 2.5.4
- Disclosed:
- Jan 6, 2018
CVE-2018-25019 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database