CVE · Critical

CVE-2020-6009 — LearnDash LMS [sfwd-lms] < 3.1.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-6009 LearnDash LMS [sfwd-lms] < 3.1.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.1.6 3.1.6 2020-04-01

CVE-2020-6009

The LearnDash LMS plugin for WordPress, in versions up to and including 3.1.5, contains an unauthenticated SQL injection flaw that allows attackers to execute arbitrary database queries without requiring user authentication. This vulnerability was resolved in version 3.1.6 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.