CVE-2025-24662: WordPress LearnDash LMS Plugin <= 4.20.0.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1.
Other sources
Missing Authorization vulnerability in LearnDash LearnDash LMS sfwd-lms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through <= 4.20.0.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24662?
CVE-2025-24662 is classified as a missing authorization vulnerability that can lead to unauthorized access.
How do I fix CVE-2025-24662?
To mitigate CVE-2025-24662, ensure that all access controls are correctly configured and update LearnDash LMS to the latest version.
What versions of LearnDash LMS are affected by CVE-2025-24662?
CVE-2025-24662 affects LearnDash LMS versions from n/a through 4.20.0.1.
What kind of manipulation can be performed due to CVE-2025-24662?
CVE-2025-24662 can allow attackers to exploit incorrectly configured access control security levels.
Who is impacted by CVE-2025-24662?
Users of LearnDash LMS and the LearnDash LMS plugin for WordPress are impacted by CVE-2025-24662.