CVE-2024-1209 describes a sensitive information exposure vulnerability in all versions of the LearnDash LMS plugin for WordPress up to and including 4.10.1. This flaw allows unauthenticated attackers to directly access and obtain uploaded assignments due to insufficient protection. The vulnerability carries a CVSS score of 5.3 (Medium), indicating a low-complexity attack that can be executed remotely without user interaction, leading to a potential loss of confidentiality. Its FAUCET Risk Score of 97/100 suggests a significant risk despite the moderate CVSS score. Currently, there is no evidence of active exploitation, and no Metasploit or ExploitDB modules are available. While Nuclei templates exist for detection, community discussion and media coverage are minimal, suggesting limited public awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.10.3CPE matchmatch criteria | cpe:2.3:a:learndash:learndash:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.