CVE-2023-3105
The LearnDash LMS plugin before version 4.6.0.1 contains a broken authentication flaw that permits unauthorized users to execute actions restricted to higher-privileged accounts, potentially leading to administrative access compromise. A threat actor could exploit this vulnerability to bypass intended access controls and perform administrative operations. The vulnerability was resolved in version 4.6.0.1 and administrators should update immediately.
Based on public CVE data (MITRE/NVD).