| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-3079 | LearnDash LMS <= 5.0.3 - Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter | StellarWP | LearnDash LMS | Medium | 6.5 | 2026-03-24 01:25:21 | Deep Dive |
| CVE-2026-2446 | Powerpack for LearnDash < 1.3.0 - Unauthenticated Arbitrary Option Update | Unknown | PowerPack for LearnDash | 超危 | - | 2026-03-06 06:00:04 | Deep Dive |
| CVE-2025-10376 | Course Redirects for Learndash Plugin <= 0.4 - Cross-Site Request Forgery | ercbs | Course Redirects for Learndash Plugin | Medium | 4.3 | 2025-10-11 09:28:43 | Deep Dive |
| CVE-2025-57988 | WordPress Uncanny Toolkit for LearnDash Plugin <= 3.7.0.3 - Cross Site Scripting (XSS) Vulnerability | Uncanny Owl | Uncanny Toolkit for LearnDash | Medium | 6.5 | 2025-09-22 18:24:24 | Deep Dive |
| CVE-2025-48080 | WordPress Uncanny Toolkit for LearnDash plugin <= 3.7.0.2 - Cross Site Scripting (XSS) Vulnerability | Uncanny Owl | Uncanny Toolkit for LearnDash | Medium | 6.5 | 2025-05-16 15:45:06 | Deep Dive |
| CVE-2025-22268 | WordPress Uncanny Toolkit for LearnDash plugin <= 3.7.0.1 - Cross Site Scripting (XSS) vulnerability | Uncanny Owl | Uncanny Toolkit for LearnDash | Medium | 6.5 | 2025-04-15 21:53:10 | Deep Dive |
| CVE-2025-24662 | WordPress LearnDash LMS Plugin <= 4.20.0.1 - Broken Access Control vulnerability | LearnDash | LearnDash LMS | Medium | 5.3 | 2025-01-27 14:22:17 | Deep Dive |
| CVE-2025-22346 | WordPress Course Migration for LearnDash plugin 1.0.2 - Server Side Request Forgery (SSRF) vulnerability | fzngagan | Course Migration for LearnDash | Medium | 6.4 | 2025-01-15 15:23:39 | Deep Dive |
| CVE-2024-37438 | WordPress Uncanny Toolkit Pro for LearnDash plugin < 4.1.4.1 - Cross Site Request Forgery (CSRF) vulnerability | Uncanny Owl | Uncanny Toolkit Pro for LearnDash | Medium | 5.4 | 2025-01-02 13:31:11 | Deep Dive |
| CVE-2023-34019 | WordPress Uncanny Toolkit for LearnDash plugin <= 3.6.4.3 - Broken Access Control vulnerability | Uncanny Owl | Uncanny Toolkit for LearnDash | Medium | 6.5 | 2024-12-13 14:23:36 | Deep Dive |
| CVE-2024-37439 | WordPress Uncanny Toolkit Pro for LearnDash plugin < 4.1.4.1 - Subscriber+ Arbitrary Post/Page Duplication vulnerability | Uncanny Owl | Uncanny Toolkit Pro for LearnDash | Medium | 5.4 | 2024-11-01 14:18:23 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-8350 | Uncanny Groups for LearnDash <= 6.1.0.1 - Missing Authorization to Authenticated (Group Leader+) User Group Add | Uncanny Owl | Uncanny Groups for LearnDash | Low | 2.7 | 2024-09-25 02:32:27 | Deep Dive |
| CVE-2024-8349 | Uncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation | Uncanny Owl | Uncanny Groups for LearnDash | High | 7.2 | 2024-09-25 02:32:26 | Deep Dive |
| CVE-2024-39656 | WordPress Tin Canny Reporting for LearnDash plugin <= 4.3.0.7 - Reflected Cross Site Scripting (XSS) vulnerability | Uncanny Owl | Tin Canny Reporting for LearnDash | High | 7.1 | 2024-08-01 21:47:16 | Deep Dive |
| CVE-2024-37436 | WordPress Uncanny Toolkit Pro for LearnDash plugin < 4.1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability | Uncanny Owl | Uncanny Toolkit Pro for LearnDash | High | 7.1 | 2024-07-22 08:16:24 | Deep Dive |
| CVE-2024-5648 | LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update | stellarwp | LearnDash LMS – Reports | Medium | 5.4 | 2024-07-09 08:33:07 | Deep Dive |
| CVE-2023-34020 | WordPress Uncanny Toolkit for LearnDash plugin <= 3.6.4.3 - Open Redirection vulnerability | Uncanny Owl | Uncanny Toolkit for LearnDash | Medium | 4.7 | 2024-03-27 13:24:44 | Deep Dive |
| CVE-2024-1208 | LearnDash LMS <= 4.10.2 - Sensitive Information Exposure via API | StellarWP | LearnDash LMS | Medium | 5.3 | 2024-02-05 21:21:58 | Deep Dive |
| CVE-2024-1209 | LearnDash LMS <= 4.10.1 - Sensitive Information Exposure via assignments | StellarWP | LearnDash LMS | Medium | 5.3 | 2024-02-05 21:21:49 | Deep Dive |