LearnDash LMS

LearnDash LMS has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2026; all 12 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 4 high. 2026 was the busiest year with 3 disclosures.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 3 of the records (25%). Other recurring categories include SQL Injection, Missing Authorization.

Every one of the 12 issues recorded for LearnDash LMS has a vendor fix available, so running the current release closes all known holes.

9 independent researchers contributed these findings, most of them (3) reported by Karl Emil Nikka.

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

12

Get automatic notifications for all LearnDash LMS vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2020-6009

LearnDash <= 3.1.5 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

12 records
2026-09-04 00:00CVE-2026-12843
5.4
Medium
Applied CyberneticsYes
2026-09-03 00:00CVE-2026-12483
7.5
High
Nguyen Ngoc Duc (duc193)Yes
2026-03-23 12:12CVE-2026-3079
6.5
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
2025-01-24 00:00CVE-2025-24662
5.3
Medium
David Ojeda GuijarroYes
2024-02-02 00:00CVE-2024-1210
5.3
Medium
Karl Emil NikkaYes
2024-02-02 00:00CVE-2024-1209
5.3
Medium
Karl Emil NikkaYes
2024-02-02 00:00CVE-2024-1208
5.3
Medium
Karl Emil NikkaYes
2023-06-27 00:00CVE-2023-3105
8.8
High
István MártonYes
2023-05-22 00:00CVE-2023-28777
8.8
High
Rafie MuhammadYes
2020-04-01 00:00CVE-2020-6009
9.8
Critical
AnonymousYes
Showing 1–10 of 12 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C