Missing Authorization Vulnerability in LearnDash LMS by LearnDash
CVE-2025-24662

5.3MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
27 January 2025

Summary

The LearnDash LMS, developed by LearnDash, is vulnerable to a missing authorization issue that results from incorrectly configured access control security levels. This vulnerability could allow unauthorized access to sensitive features or content of the LMS, impacting its overall security posture. It is crucial for users to apply the latest updates and configurations to mitigate potential exploitation of this vulnerability, especially in versions up to 4.20.0.1.

Affected Version(s)

LearnDash LMS <= 4.20.0.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David Ojeda Guijarro (Patchstack Alliance)
.