July 12, 2023, 5:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts.

access account account access attackers authorization bypass change cve insecure lms object passwords plugin resources system vulnerable wordpress

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

IT Security Associate

@ EcoVadis | Barcelona, Spain

Cyber Security w/ Clearance - Alabama

@ Rothe | Huntsville, AL, United States

Manager - Cyber Security

@ Adani Group | AHMEDABAD, GUJARAT, India

Security Architect

@ Wix | Tel Aviv-Yafo, Israel

Technical Support Engineer - Cyber Security

@ Microsoft | Taipei, Taipei City, Taiwan