S4E just found a medium log file scanner
medium·Product Based Web Vulnerabilities·Updated Feb 26, 2024

CVE-2024-1210 Scanner

CVE-2024-1210 scanner - Information Disclosure vulnerability in LearnDash LMS plufin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-1210
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnDash LMSby StellarWP
0
Updated Aug 22, 2026View on NVD →
Detail

Vulnerability Overview

The LearnDash LMS plugin for WordPress, up to version 4.10.1, exposes sensitive information via an API endpoint. This vulnerability allows unauthenticated users to access quiz details, posing a risk of information leakage.

Vulnerability Details

The vulnerability is present in the /wp-json/ldlms/v1/sfwd-quiz API endpoint, which fails to properly restrict access to quiz information. This scanner probes the endpoint for typical quiz attributes, such as id and quiz_materials, to confirm the presence of this exposure.

Possible Effects

  • Unauthorized access to quiz details.
  • Potential exposure of quiz contents and materials.
  • Risk of compromising quiz integrity and confidentiality.

Why Choose S4E

S4E offers a comprehensive platform to detect and mitigate vulnerabilities like the one in LearnDash LMS. Our advanced scanning tools and expert guidance help you:

  • Stay ahead of potential security threats with timely detection.
  • Receive actionable insights and recommendations for effective remediation.
  • Ensure continuous protection through regular updates and monitoring.

References

Solution Advice
  • Update to Version 4.10.2: Upgrade your LearnDash LMS plugin to version 4.10.2 or later, where this vulnerability has been addressed.
  • Review API Access Controls: Ensure that API endpoints are properly secured and only accessible to authenticated and authorized users.
  • Regular Security Audits: Conduct regular security audits of your WordPress plugins and themes to identify and mitigate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.