WordPress 的 LearnDash LMS 插件在 4.25.0 至 5.1.6 版本中存在授权绕过漏洞。该漏洞源于插件未能正确验证用户是否被授权执行特定操作。这使得未认证的攻击者能够绕过整个支付系统,在未完成支付验证的情况下将任意用户注册到付费课程中,从而获得对高级教育内容的未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| StellarWP | LearnDash LMS | 4.25.0≤ 5.1.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| StellarWP | LearnDash LMS | 4.25.0 ~ 5.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet