CVE Database /
CVE-2020-6009
CVE · Critical
CVE-2020-6009 — LearnDash LMS [sfwd-lms] < 3.1.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-6009
|
LearnDash LMS [sfwd-lms] < 3.1.6 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 3.1.6
|
3.1.6 |
2020-04-01 |
—
|
CVE-2020-6009
The LearnDash LMS plugin for WordPress, in versions up to and including 3.1.5, contains an unauthenticated SQL injection flaw that allows attackers to execute arbitrary database queries without requiring user authentication. This vulnerability was resolved in version 3.1.6 and later releases.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings