Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Learndash

First CVE: Jan 16, 2020Active for: 7 yearsTotal CVEs: 11
39.8
VTI Score
Medium

Learndash is a modestly represented learning-management-system plugin whose vulnerabilities concentrate in a single, widely deployed product used across educational and training platforms. The exposure recurs through application-layer weakness classes including cross-site scripting, SQL injection, authorization bypass, and sensitive-information disclosure, alongside input-validation and access-control gaps characteristic of web-facing educational software; vulnerabilities affecting this vendor frequently acquire public exploit code. Defenders should treat Learndash plugin updates as part of their WordPress and learning-platform maintenance routine; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Learndash over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2020
6 years ago
Most Recent CVE
Feb 12, 2025
527 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-6009CRITICAL
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
Apr 1, 20209.831NONO
CVE-2020-7108MEDIUM
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
Jan 16, 20205.429NOYES
CVE-2024-1208MEDIUM
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthentica
Feb 5, 20245.328NOYES
CVE-2024-1210MEDIUM
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthentica
Feb 5, 20245.327NOYES
CVE-2024-1209MEDIUM
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient prote
Feb 5, 20245.327NOYES
CVE-2023-3105HIGH
The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controll
Jul 12, 20238.826NONO
CVE-2018-25019HIGH
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which
Nov 1, 20217.524NONO
CVE-2023-28777HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS:
Oct 31, 20238.822NONO
CVE-2024-56940HIGH
An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.
Feb 12, 20257.520NONO
CVE-2024-56939MEDIUM
LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.
Feb 12, 20255.416NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
36%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
27.3% of CVEs· 98th percentile
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Learndash.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Learndash — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Learndash's Products

View all 5 CNAs →

Top CWEs