CVE-2018-25019: LearnDash < 2.5.4 - Unauthenticated Arbitrary File Upload
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndashassignmentprocessinit() function, which could allow unauthenticated users to upload arbitrary files to the web server
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-25019?
CVE-2018-25019 is a vulnerability in the LearnDash LMS WordPress plugin before version 2.5.4 that allows unauthenticated users to upload arbitrary files to the web server.
What is the severity of CVE-2018-25019?
CVE-2018-25019 has a severity rating of 7.5 (high).
How does CVE-2018-25019 occur?
CVE-2018-25019 occurs due to the lack of authorization and validation of the file to be uploaded in the learndash_assignment_process_init() function.
How can CVE-2018-25019 be exploited?
CVE-2018-25019 can be exploited by unauthenticated users who are able to upload arbitrary files to the web server.
What is the affected software for CVE-2018-25019?
The affected software for CVE-2018-25019 is the LearnDash LMS WordPress plugin before version 2.5.4.