N/A
2026-03-23< 5.0.3.1
LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter
Minimum safe version
5.0.3.1
Update to 5.0.3.1 or later to address 13 fixable vulnerabilities
LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter
CVE-2025-24662
CVE-2024-1208
CVE-2024-1209
CVE-2024-1210
LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via API
LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments
CVE-2023-3105
CVE-2023-28777
CVE-2020-7108
WordPress LearnDash LMS premium plugin <= 3.1.5 - Unauthenticated SQL Injection (SQLi) vulnerability
CVE-2018-25019