Learndash Lms
Stellarwp · 5 CVEs
CVE-2026-12843
MEDIUM
LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint
Sep 5, 2026
CVE-2026-12483
HIGH
LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler
Sep 4, 2026
CVE-2026-3079
MEDIUM
LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter
Mar 24, 2026
CVE-2024-1208
MEDIUM
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
Feb 5, 2024
CVE-2024-1210
MEDIUM
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API
Feb 5, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-12843 | LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint | MEDIUM | 0.16% | Sep 5, 2026 |
| CVE-2026-12483 | LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler | HIGH | 0.38% | Sep 4, 2026 |
| CVE-2026-3079 | LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter | MEDIUM | 0.46% | Mar 24, 2026 |
| CVE-2024-1208 | LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API | MEDIUM | 5.29% | Feb 5, 2024 |
| CVE-2024-1210 | LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API | MEDIUM | 2.03% | Feb 5, 2024 |
Showing 1 to 5 of 5 CVEs