Impact
The LearnDash LMS plugin for WordPress contains a missing authorization check in versions 4.25.0 through 5.1.6. Because the plugin does not verify that a user is authorized to perform enrollment actions, unauthenticated attackers can enroll any user into paid courses. This bypasses the entire payment verification process and gives unauthorized users access to premium educational content. The weakness is classified as CWE‑862, representing a missing or incomplete authorization control.
Affected Systems
StellarWP’s LearnDash LMS plugin for WordPress is affected, specifically versions 4.25.0 through 5.1.6. Users running those versions in any WordPress installation are vulnerable until the plugin is updated beyond 5.1.6.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack can be carried out without authentication by sending an unauthorized REST request that triggers the enrollment logic. Given the absence of a required credential, the likelihood of exploitation is non‑negligible, especially for sites offering paid courses. Organizations should view this as a potential vector for unauthorized content access and take remediation promptly.
OpenCVE Enrichment