CVE · High

CVE-2018-25019 — LearnDash LMS [sfwd-lms] < 2.5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-25019 LearnDash LMS [sfwd-lms] < 2.5.4 Unrestricted Upload of File with Dangerous Type High 7.5 < 2.5.4 2.5.4 2018-01-06

CVE-2018-25019

The LearnDash LMS plugin before version 2.5.4 contains a file upload vulnerability in the learndash_assignment_process_init() function that lacks proper authorization checks and input validation. This flaw permits unauthenticated attackers to upload arbitrary files to the server. The issue was remedied in version 2.5.4 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.