CVE-2024-1209: LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1209?
CVE-2024-1209 is rated as having a medium severity due to the risk of unauthorized access to sensitive information.
How do I fix CVE-2024-1209?
To fix CVE-2024-1209, upgrade the LearnDash LMS plugin to version 4.10.2 or later.
What types of sensitive information are exposed in CVE-2024-1209?
CVE-2024-1209 can expose uploaded assignments, which may contain personal and sensitive user data.
Who is affected by CVE-2024-1209?
All users of the LearnDash LMS plugin for WordPress up to and including version 4.10.1 are affected by CVE-2024-1209.
Can CVE-2024-1209 be exploited by authenticated users?
No, CVE-2024-1209 can be exploited by unauthenticated attackers, making it particularly concerning.