CVE Database /
CVE-2018-25019
CVE · High
CVE-2018-25019 — LearnDash LMS [sfwd-lms] < 2.5.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-25019
|
LearnDash LMS [sfwd-lms] < 2.5.4 |
Unrestricted Upload of File with Dangerous Type |
High
7.5
|
< 2.5.4
|
2.5.4 |
2018-01-06 |
—
|
CVE-2018-25019
The LearnDash LMS plugin before version 2.5.4 contains a file upload vulnerability in the learndash_assignment_process_init() function that lacks proper authorization checks and input validation. This flaw permits unauthenticated attackers to upload arbitrary files to the server. The issue was remedied in version 2.5.4 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings