Learndash is a modestly represented learning-management-system plugin whose vulnerabilities concentrate in a single, widely deployed product used across educational and training platforms. The exposure recurs through application-layer weakness classes including cross-site scripting, SQL injection, authorization bypass, and sensitive-information disclosure, alongside input-validation and access-control gaps characteristic of web-facing educational software; vulnerabilities affecting this vendor frequently acquire public exploit code. Defenders should treat Learndash plugin updates as part of their WordPress and learning-platform maintenance routine; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Learndash over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-6009CRITICAL LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. | Apr 1, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-7108MEDIUM The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. | Jan 16, 2020 | 5.4 | 29 | NO | YES |
CVE-2024-1208MEDIUM The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthentica | Feb 5, 2024 | 5.3 | 28 | NO | YES |
CVE-2024-1210MEDIUM The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthentica | Feb 5, 2024 | 5.3 | 27 | NO | YES |
CVE-2024-1209MEDIUM The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient prote | Feb 5, 2024 | 5.3 | 27 | NO | YES |
CVE-2023-3105HIGH The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controll | Jul 12, 2023 | 8.8 | 26 | NO | NO |
CVE-2018-25019HIGH The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which | Nov 1, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-28777HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: | Oct 31, 2023 | 8.8 | 22 | NO | NO |
CVE-2024-56940HIGH An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads. | Feb 12, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-56939MEDIUM LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class. | Feb 12, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Learndash.
Media articles that mention a CVE ID that affects a product developed by Learndash — matched by CVE ID, not by vendor name.