Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2024-11-21

CVE-2024-1210 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

PLUGIN Learndash

CVE-2024-1210

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1209 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

PLUGIN Learndash

CVE-2024-1209

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2024-1208 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

PLUGIN Learndash

CVE-2024-1208

MEDIUM CVSS 5.3 2024-02-05
Threat Entry Updated 2024-11-21

CVE-2023-3105 - Learndash Plugin

The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts.

PLUGIN Learndash

CVE-2023-3105

HIGH CVSS 8.8 2023-07-12
Scroll to top