Impact
The Course Redirects for Learndash plugin for WordPress contains a missing nonce validation on the settings page, which allows an unauthenticated attacker to forge a request and alter plugin settings. This is a classic CSRF flaw (CWE-352) that can affect site behavior and user experience by applying unauthorized configuration changes. The flaw does not directly expose data or execute arbitrary code, but it enables an attacker to modify settings that could lead to further exploitation or service disruption.
Affected Systems
WordPress installations that use the Course Redirects for Learndash plugin from ercbs, specifically any version up to and including 0.4. Sites that have this plugin installed and have active administrator accounts are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation. This vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is social engineering: an attacker needs to lure a site administrator into clicking a crafted link or submitting a forged form that targets the settings page. Because the exploit requires administrator interaction and does not require privileged credentials or local network access, the overall risk is moderate but the chance of real-world exploitation is low.
OpenCVE Enrichment