Missing Authorization Vulnerability in LearnDash LMS by LearnDash
CVE-2025-24662
5.3MEDIUM
Summary
The LearnDash LMS, developed by LearnDash, is vulnerable to a missing authorization issue that results from incorrectly configured access control security levels. This vulnerability could allow unauthorized access to sensitive features or content of the LMS, impacting its overall security posture. It is crucial for users to apply the latest updates and configurations to mitigate potential exploitation of this vulnerability, especially in versions up to 4.20.0.1.
Affected Version(s)
LearnDash LMS <= 4.20.0.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
David Ojeda Guijarro (Patchstack Alliance)