PLUGIN SECURITY

Is Sfwd Lms safe?

The strongest CAPTCHA. Switch from reCAPTCHA and Turnstile for free. Works with 60+ integrations: Contact Form 7, Elementor, WooCommerce, Divi, etc.

What this plugin does

  • Slug: sfwd-lms
  • Author: hcaptcha
  • 70000+ active installs
  • 92/100 rating (86 reviews on wordpress.org)
  • 2150028 all-time downloads
  • On WordPress.org since 2019-05-02

antispamcaptchahcaptcharecaptchaspam

Maintenance status

  • Latest known version: 5.2.0
  • Last updated: 2026-08-06 1:13pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+

Known vulnerabilities

10 known CVEs on file for Sfwd Lms.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-24662 LearnDash LMS [sfwd-lms] < 4.20.0.3 Missing Authorization Medium 5.3 < 4.20.0.3 4.20.0.3 2025-01-24 ✓ fixed in latest
CVE-2024-1209 LearnDash LMS [sfwd-lms] < 4.10.2 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 4.10.2 4.10.2 2024-02-02 ✓ fixed in latest
CVE-2024-1210 LearnDash LMS [sfwd-lms] < 4.10.2 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 4.10.2 4.10.2 2024-02-02 ✓ fixed in latest
CVE-2024-1208 LearnDash LMS [sfwd-lms] < 4.10.3 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 4.10.3 4.10.3 2024-02-02 ✓ fixed in latest
CVE-2023-3105 LearnDash LMS [sfwd-lms] < 4.6.0.1 Authorization Bypass Through User-Controlled Key High 8.8 < 4.6.0.1 4.6.0.1 2023-06-27 ✓ fixed in latest
CVE-2023-28777 LearnDash LMS [sfwd-lms] < 4.5.3.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 4.5.3.1 4.5.3.1 2023-05-22 ✓ fixed in latest
CVE-2020-6009 LearnDash LMS [sfwd-lms] < 3.1.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.1.6 3.1.6 2020-04-01 ✓ fixed in latest
CVE-2020-7108 LearnDash LMS [sfwd-lms] < 3.1.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.1.2 3.1.2 2020-01-15 ✓ fixed in latest
+ 6 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-25019 LearnDash LMS [sfwd-lms] < 2.5.4 Unrestricted Upload of File with Dangerous Type High 7.5 < 2.5.4 2.5.4 2018-01-06 ✓ fixed in latest
LearnDash LMS [sfwd-lms] < 5.0.3.1 Unknown < 5.0.3.1 5.0.3.1 0000-00-00 ✓ fixed in latest
CVE-2024-1210 LearnDash LMS < 4.10.2 - Sensitive Information Exposure via API Unknown < 4.10.2 4.10.2 ✓ fixed in latest
CVE-2024-1209 LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments Unknown < 4.10.2 4.10.2 ✓ fixed in latest
CVE-2024-1208 LearnDash LMS < 4.10.3 - Sensitive Information Exposure via API Unknown < 4.10.3 4.10.3 ✓ fixed in latest
CVE-2026-3079 LearnDash LMS < 5.0.3.1 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter Unknown < 5.0.3.1 5.0.3.1 ✓ fixed in latest

How to fix it

Keep Sfwd Lms updated — 5.2.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.