plugin

Uncanny Learndash Toolkit Vulnerabilities

14 known security issues reported for the Uncanny Learndash Toolkit WordPress plugin. Most recent disclosed Sep 22, 2025.

2 high 5 medium

Running Uncanny Learndash Toolkit on your site? Check whether your installed version is affected.

Scan your site free

Uncanny Toolkit for LearnDash <= 3.7.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 3.7.0.3
Fixed in:
3.7.0.4
Disclosed:
Sep 22, 2025

CVE-2025-57988 on NVD →

Uncanny Toolkit for LearnDash <= 3.7.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 3.7.0.2
Fixed in:
3.7.0.3
Disclosed:
May 16, 2025

CVE-2025-48080 on NVD →

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.7.0.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Stored XSS. This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.7.0.2.

Affected:
up to 3.7.0.3
Fixed in:
3.7.0.3
Disclosed:
May 16, 2025

CVE-2025-48080 on NVD →

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.7.0.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Stored XSS. This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.7.0.1.

Affected:
up to 3.7.0.2
Fixed in:
3.7.0.2
Disclosed:
Apr 15, 2025

CVE-2025-22268 on NVD →

Uncanny Toolkit for LearnDash <= 3.7.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web s...

CVSS:
6.4
Affected:
up to 3.7.0.1
Fixed in:
3.7.0.2
Disclosed:
Apr 11, 2025

CVE-2025-22268 on NVD →

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.6.4.4

unknown

[en] Missing Authorization vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.

Affected:
up to 3.6.4.4
Fixed in:
3.6.4.4
Disclosed:
Dec 13, 2024

CVE-2023-34019 on NVD →

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.6.4.4

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.

Affected:
up to 3.6.4.4
Fixed in:
3.6.4.4
Disclosed:
Mar 27, 2024

CVE-2023-34020 on NVD →

Uncanny Toolkit for LearnDash <= 3.6.4.3 - Missing Authorization via review-banner-visibility REST route

medium

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the review-banner-visibility REST route in versions up to, and including, 3.6.4.3. This makes it possible for unauthenticated attackers to save review settings.

CVSS:
6.5
Affected:
up to 3.6.4.3
Fixed in:
3.6.4.4
Disclosed:
Jun 2, 2023

CVE-2023-34019 on NVD →

Uncanny Toolkit for LearnDash <= 3.6.4.3 - Open Redirect

medium

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.6.4.3. This is due to insufficient validation on the redirect url supplied via the 'redirect_url' parameter of the /review-banner-visibility/ REST API endpoint. This makes it possible for unauthenti...

CVSS:
4.3
Affected:
up to 3.6.4.4
Fixed in:
3.6.4.4
Disclosed:
Jun 1, 2023

CVE-2023-34020 on NVD →

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.6.4.4

unknown

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 3.6.4.3. This is due to insufficient validation on the redirect url supplied via the 'redirect_url' parameter of the /review-banner-visibility/ REST API endpoint. This makes it possible for unauthenti...

Affected:
up to 3.6.4.4
Fixed in:
3.6.4.4
Disclosed:
Jun 1, 2023

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.6.4.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions.

Affected:
up to 3.6.4.2
Fixed in:
3.6.4.2
Disclosed:
May 26, 2023

CVE-2023-23714 on NVD →

Uncanny Toolkit for LearnDash <= 3.6.4.1 - Cross-Site Request Forgery to Arbitrary Plugin Install and Activation

high

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.4.1. This is due to missing or incorrect nonce validation on the wp_ajax_auto_plugin_install function. This makes it possible for unauthenticated attackers to install or activate arbi...

CVSS:
8.8
Affected:
up to 3.6.4.1
Fixed in:
3.6.4.2
Disclosed:
Jan 27, 2023

CVE-2023-23714 on NVD →

Uncanny Toolkit for LearnDash <= 3.6.3 - Cross-Site Request Forgery

high

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing nonce validation on several functions such as the ajax_activate_deactivate_module function. This makes it possible for unauthenticated attackers to change p...

CVSS:
8.8
Affected:
up to 3.6.3
Fixed in:
3.6.4
Disclosed:
Nov 26, 2022

Uncanny Toolkit for LearnDash [uncanny-learndash-toolkit] < 3.6.4

unknown

The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing nonce validation on several functions such as the ajax_activate_deactivate_module function. This makes it possible for unauthenticated attackers to change p...

Affected:
up to 3.6.4
Fixed in:
3.6.4
Disclosed:
Nov 26, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database