Cross-Site Request Forgery in Course Redirects Plugin for WordPress by Learndash
CVE-2025-10376
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2025
What is CVE-2025-10376?
The Course Redirects for Learndash plugin for WordPress is prone to a Cross-Site Request Forgery (CSRF) vulnerability due to inadequate nonce validation during form submissions on the settings page. This flaw allows unauthenticated individuals to alter plugin settings by orchestrating a forged request, provided they can deceive an administrator into executing an action, such as clicking on a malicious link. It's important for site administrators to remain vigilant and ensure proper security measures are in place to mitigate this risk.
Affected Version(s)
Course Redirects for Learndash Plugin * <= 0.4