CVE · High

CVE-2023-3105 — LearnDash LMS [sfwd-lms] < 4.6.0.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3105 LearnDash LMS [sfwd-lms] < 4.6.0.1 Authorization Bypass Through User-Controlled Key High 8.8 < 4.6.0.1 4.6.0.1 2023-06-27

CVE-2023-3105

The LearnDash LMS plugin before version 4.6.0.1 contains a broken authentication flaw that permits unauthorized users to execute actions restricted to higher-privileged accounts, potentially leading to administrative access compromise. A threat actor could exploit this vulnerability to bypass intended access controls and perform administrative operations. The vulnerability was resolved in version 4.6.0.1 and administrators should update immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.