QID 731200
QID 731200: LearnDash LMS plugin for WordPress Insufficient Information Vulnerability
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
Affected version
LearnDash LMS plugin for WordPress prior to 4.10.3
QID Detection Logic (Un-authenticated):
This QID sends GET request to /wp-json/wp/v2/sfwd-question to check for sensitive information exposure.
On successful exploitation it allows unauthenticated attackers to obtain access to quiz questions.
Solution
Vendor has released fix. Refer to release notes 4.10.3
Vendor References
- LearbDash -
www.learndash.com/release-notes/
CVEs related to QID 731200
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| LearnDash 4.10.3 |
|