Impact
Missing authorization in LearnDash LMS allows attackers to exploit incorrectly configured security levels, enabling them to view or download course materials that should be restricted. This Broken Access Control flaw permits any authenticated or potentially unauthenticated user to gain access to content beyond their permission level, compromising confidentiality and possibly enabling further lateral movement within the WordPress site.
Affected Systems
WordPress sites running the LearnDash LMS plugin version 4.20.0.1 or earlier are impacted. The vulnerability applies to all installations of LearnDash LMS from the earliest available release up to and including 4.20.0.1.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1% suggests that the likelihood of exploitation in the near term is low, and the vulnerability is not yet in CISA’s KEV catalog. Nevertheless, the flaw can be triggered by sending crafted requests to protected learning resources, and based on the description it can be inferred that the attack vector is web‑based and does not require additional credentials.
OpenCVE Enrichment
EUVD