WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Sfwd Lms?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Sfwd Lms — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: sfwd-lms
  • 70000+ instalaciones activas

antispamcaptchahcaptcharecaptchaspam

Estado de mantenimiento

  • Última versión conocida: 5.1.0
  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

10 CVEs conocidos registrados para Sfwd Lms.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-24662 LearnDash LMS [sfwd-lms] < 4.20.0.3 Falta de control de autorización Media 5,3 < 4.20.0.3 4.20.0.3 2025-01-24 ✓ corregido en la última versión
CVE-2024-1210 LearnDash LMS [sfwd-lms] < 4.10.2 Exposición de información sensible a un actor no autorizado Media 5,3 < 4.10.2 4.10.2 2024-02-05 ✓ corregido en la última versión
CVE-2024-1209 LearnDash LMS [sfwd-lms] < 4.10.2 Exposición de información sensible a un actor no autorizado Media 5,3 < 4.10.2 4.10.2 2024-02-05 ✓ corregido en la última versión
CVE-2024-1208 LearnDash LMS [sfwd-lms] < 4.10.3 Exposición de información sensible a un actor no autorizado Media 5,3 < 4.10.3 4.10.3 2024-02-05 ✓ corregido en la última versión
LearnDash LMS [sfwd-lms] < 4.10.2 Desconocido < 4.10.2 4.10.2 2024-02-02 ✓ corregido en la última versión
LearnDash LMS [sfwd-lms] < 4.10.2 Desconocido < 4.10.2 4.10.2 2024-02-02 ✓ corregido en la última versión
LearnDash LMS [sfwd-lms] < 4.10.3 Desconocido < 4.10.3 4.10.3 2024-02-02 ✓ corregido en la última versión
CVE-2023-3105 LearnDash LMS [sfwd-lms] < 4.6.0.1 Elusión de autorización mediante una clave controlada por el usuario Alta 8,8 < 4.6.0.1 4.6.0.1 2023-06-27 ✓ corregido en la última versión

CVE-2025-24662

The LearnDash LMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.20.0.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-1210

Update the WordPress LearnDash LMS plugin to the latest available version (at least 4.10.2). Karl Emil Nikka discovered and reported this Sensitive Data Exposure vulnerability in WordPress LearnDash LMS Plugin. This vulnerability has been fixed in version 4.10.2. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1209

Update the WordPress LearnDash LMS plugin to the latest available version (at least 4.10.2). Karl Emil Nikka discovered and reported this Sensitive Data Exposure vulnerability in WordPress LearnDash LMS Plugin. This vulnerability has been fixed in version 4.10.2. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1208

Update the WordPress LearnDash LMS plugin to the latest available version (at least 4.10.3). Karl Emil Nikka discovered and reported this Sensitive Data Exposure vulnerability in WordPress LearnDash LMS Plugin. This vulnerability has been fixed in version 4.10.3. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

LearnDash LMS [sfwd-lms] < 4.10.2

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

LearnDash LMS [sfwd-lms] < 4.10.2

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

LearnDash LMS [sfwd-lms] < 4.10.3

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-3105

Update the WordPress LearnDash LMS plugin to the latest available version (at least 4.6.0.1). Lana Codes discovered and reported this Broken Authentication vulnerability in WordPress LearnDash LMS Plugin. This can be abused by a malicious actor to perform action which normally should only be able to be executed by higher privileged users. These actions might allow the malicious actor to gain admin access to the website. This vulnerability has been fixed in version 4.6.0.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 5 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2023-28777 LearnDash LMS [sfwd-lms] < 4.5.3.1 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 8,5 < 4.5.3.1 4.5.3.1 2023-05-22 ✓ corregido en la última versión
CVE-2020-6009 LearnDash LMS [sfwd-lms] < 3.1.6 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Crítica 9,8 < 3.1.6 3.1.6 2020-04-01 ✓ corregido en la última versión
CVE-2020-7108 LearnDash LMS [sfwd-lms] < 3.1.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.1.2 3.1.2 2020-01-15 ✓ corregido en la última versión
CVE-2018-25019 LearnDash LMS [sfwd-lms] < 2.5.4 Carga de archivos sin restricción de tipo peligroso Alta 7,5 < 2.5.4 2.5.4 2018-01-06 ✓ corregido en la última versión
CVE-2026-3079 LearnDash LMS [sfwd-lms] < 5.0.3.1 Desconocido < 5.0.3.1 5.0.3.1 0000-00-00 ✓ corregido en la última versión

CVE-2023-28777

The LearnDash LMS plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 4.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2020-6009

Unauthenticated SQL Injection (SQLi) vulnerability discovered in WordPress LearnDash LMS premium plugin (versions <= 3.1.5).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2020-7108

Reflected Cross Site Scripting (XSS) issue on the [ld_profile] search field. First reported to Learndash on January 14, 2020, and update 3.1.2 to fix it was released same day. This report is based on an email LearnDash sent out to their users on January 14, 2020.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2018-25019

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-3079

The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' parameter in the 'learndash_propanel_template' AJAX action in all versions up to, and including, 5.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Mantén Sfwd Lms actualizado — 5.1.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.