plugin

Sfwd Lms Vulnerabilities

23 known security issues reported for the Sfwd Lms WordPress plugin. Most recent disclosed Mar 24, 2026.

1 critical 4 high 6 medium

Running Sfwd Lms on your site? Check whether your installed version is affected.

Scan your site free

LearnDash LMS - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter vulnerability

high

Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter vulnerability

CVSS:
8.5
Affected:
up to 5.0.3
Fixed in:
5.0.3.1
Disclosed:
Mar 24, 2026

LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter

medium

The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

CVSS:
6.5
Affected:
up to 5.0.3
Fixed in:
5.0.3.1
Disclosed:
Mar 23, 2026

CVE-2026-3079 on NVD →

LearnDash LMS [sfwd-lms] < 4.20.0.3

unknown

[en] Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1.

Affected:
up to 4.20.0.3
Fixed in:
4.20.0.3
Disclosed:
Jan 27, 2025

CVE-2025-24662 on NVD →

LearnDash LMS <= 4.20.0.1 - Missing Authorization

medium

The LearnDash LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.20.0.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.20.0.1
Fixed in:
4.20.0.3
Disclosed:
Jan 24, 2025

CVE-2025-24662 on NVD →

LearnDash LMS [sfwd-lms] < 4.10.3

unknown

[en] The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

Affected:
up to 4.10.3
Fixed in:
4.10.3
Disclosed:
Feb 5, 2024

CVE-2024-1208 on NVD →

LearnDash LMS [sfwd-lms] < 4.10.2

unknown

[en] The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

Affected:
up to 4.10.2
Fixed in:
4.10.2
Disclosed:
Feb 5, 2024

CVE-2024-1209 on NVD →

LearnDash LMS [sfwd-lms] < 4.10.2

unknown

[en] The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

Affected:
up to 4.10.2
Fixed in:
4.10.2
Disclosed:
Feb 5, 2024

CVE-2024-1210 on NVD →

LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API

medium

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

CVSS:
5.3
Affected:
up to 4.10.1
Fixed in:
4.10.2
Disclosed:
Feb 2, 2024

CVE-2024-1210 on NVD →

LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments

medium

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

CVSS:
5.3
Affected:
up to 4.10.1
Fixed in:
4.10.2
Disclosed:
Feb 2, 2024

CVE-2024-1209 on NVD →

LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API

medium

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

CVSS:
5.3
Affected:
up to 4.10.2
Fixed in:
4.10.3
Disclosed:
Feb 2, 2024

CVE-2024-1208 on NVD →

LearnDash LMS [sfwd-lms] < 4.10.3

unknown

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

Affected:
up to 4.10.3
Fixed in:
4.10.3
Disclosed:
Feb 2, 2024

LearnDash LMS [sfwd-lms] < 4.10.2

unknown

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

Affected:
up to 4.10.2
Fixed in:
4.10.2
Disclosed:
Feb 2, 2024

LearnDash LMS [sfwd-lms] < 4.10.2

unknown

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

Affected:
up to 4.10.2
Fixed in:
4.10.2
Disclosed:
Feb 2, 2024

LearnDash LMS [sfwd-lms] < 4.5.3.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3.

Affected:
up to 4.5.3.1
Fixed in:
4.5.3.1
Disclosed:
Oct 31, 2023

CVE-2023-28777 on NVD →

LearnDash LMS [sfwd-lms] < 4.6.0.1

unknown

[en] The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with e...

Affected:
up to 4.6.0.1
Fixed in:
4.6.0.1
Disclosed:
Jul 12, 2023

CVE-2023-3105 on NVD →

LearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

high

The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existi...

CVSS:
8.8
Affected:
up to 4.6.0
Fixed in:
4.6.0.1
Disclosed:
Jun 27, 2023

CVE-2023-3105 on NVD →

LearnDash LMS <= 4.5.3 - Authenticated (Contributor+) SQL Injection

high

The LearnDash LMS plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contr...

CVSS:
8.8
Affected:
up to 4.5.3
Fixed in:
4.5.3.1
Disclosed:
May 22, 2023

CVE-2023-28777 on NVD →

LearnDash LMS [sfwd-lms] < 2.5.4

unknown

[en] The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Nov 1, 2021

CVE-2018-25019 on NVD →

LearnDash <= 3.1.5 - Unauthenticated SQL Injection

critical

LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

CVSS:
9.8
Affected:
up to 3.1.5
Fixed in:
3.1.6
Disclosed:
Apr 1, 2020

CVE-2020-6009 on NVD →

LearnDash LMS [sfwd-lms] < 3.1.6

unknown

[en] LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

Affected:
up to 3.1.6
Fixed in:
3.1.6
Disclosed:
Apr 1, 2020

CVE-2020-6009 on NVD →

LearnDash LMS [sfwd-lms] < 3.1.2

unknown

[en] The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jan 16, 2020

CVE-2020-7108 on NVD →

LearnDash 3.0.0-3.1.1 - Reflected Cross Site Scripting issue on the [ld_profile] search field

medium

The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.

CVSS:
6.1
Affected:
3.0.0 – 3.1.1
Fixed in:
3.1.2
Disclosed:
Jan 15, 2020

CVE-2020-7108 on NVD →

LearnDash LMS <= 2.5.3 - Arbitrary File Upload

high

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

CVSS:
7.5
Affected:
up to 2.5.4
Fixed in:
2.5.4
Disclosed:
Jan 6, 2018

CVE-2018-25019 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database