S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Apr 30, 2024

CVE-2024-1208 Scanner

CVE-2024-1208 scanner - Sensitive Information Exposure in LearnDash LMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
5
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-1208
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnDash LMSby StellarWP
0
Updated Aug 22, 2026View on NVD →
Detail

LearnDash LMS, a WordPress plugin, is utilized by various educational institutions, instructors, and organizations for managing and delivering online learning content and assessments. This vulnerability checker focuses on detecting sensitive information exposure vulnerabilities present in LearnDash LMS versions up to 4.10.2, potentially impacting the confidentiality of quiz questions and assessment details accessible via the plugin's API.

The vulnerability detected in LearnDash LMS involves sensitive information exposure through its API, affecting versions up to 4.10.2. Due to inadequate access controls, unauthenticated attackers can access quiz questions and related details via the '/wp-json/wp/v2/sfwd-question' endpoint, compromising the confidentiality of assessment content and potentially exposing sensitive information.

The vulnerability manifests when unauthenticated attackers make GET requests to the '/wp-json/wp/v2/sfwd-question' endpoint of a WordPress site hosting LearnDash LMS. By analyzing JSON responses, attackers can obtain quiz question details, including question type and total points, which should only be accessible to authorized users. This exposure poses a risk of unauthorized access to sensitive assessment content.

Exploiting the sensitive information exposure vulnerability in LearnDash LMS may lead to unauthorized disclosure of quiz questions, assessment details, and other sensitive educational content. Malicious actors can access and potentially misuse quiz questions for academic dishonesty, compromise the integrity of assessments, and undermine the trust and effectiveness of online learning environments.

Safeguard your online learning platform from the risks associated with sensitive information exposure vulnerabilities by leveraging the comprehensive security scanning capabilities offered by the S4E platform. Join our platform to proactively identify and remediate vulnerabilities like CVE-2024-1208, ensuring the confidentiality and integrity of your educational content and protecting the trust of your learners.

 

References

Solution Advice
  • Upgrade LearnDash LMS plugin to version 4.10.3 or later to mitigate the sensitive information exposure vulnerability.
  • Implement access controls and authentication mechanisms to restrict unauthorized access to quiz questions and assessment content exposed via the plugin's API.
  • Regularly review and audit API endpoints and permissions to ensure proper access controls are enforced, preventing unauthorized access to sensitive educational materials.
  • Educate administrators and instructors on secure API usage practices and the importance of protecting sensitive information in online learning environments.
  • Monitor API access logs and implement intrusion detection systems (IDS) to detect and mitigate unauthorized attempts to access quiz questions and assessment content.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.