Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12483— LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler

Quick assessment

Affected
StellarWP LearnDash LMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 LearnDash LMS 插件在 5.1.5 及以下版本中存在不受限制的文件类型上传漏洞。该漏洞源于 函数中输入验证不足:该函数遍历整个数组,但仅对第一个文件进行校验。这使得具有订阅者(subscriber)及以上权限、且注册在启用作业上传功能的课程中的认证攻击者,能够向服务器的 目录上传任意不允许的文件类型(包括 PHP 文件)。 需要注意的是,只有当默认服务器配置被修改以允许文件执行时,上传的文件才可用于远程代码执行(RCE)。

CVSS 7.5 · High EPSS 0.38% · P31

Affected Version Matrix 1

VendorProduct Version RangeStatus
StellarWP LearnDash LMS ≤ 5.1.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12483

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler
Source: CVE Program / CVE List V5
Vulnerability Description
The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for authenticated attackers, with subscriber-level access and above who are enrolled in a course with assignment uploads enabled, to upload arbitrary disallowed files, including PHP files, to the server's wp-content/uploads/learndash/assignments/ directory. The uploaded files can only be used for Remote Code Execution if default server configurations have been changed to allow for execution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
StellarWP LearnDash LMS 0 ~ 5.1.5 -

II. Public POCs for CVE-2026-12483

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12483

登录查看更多情报信息。

Vendor Pages for CVE-2026-12483 (1)

Other References for CVE-2026-12483 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12483

No comments yet


Leave a comment