S4E just found a medium log file scanner
medium·Product Based Web Vulnerabilities·Updated Apr 30, 2024

CVE-2024-1209 Scanner

CVE-2024-1209 scanner - Sensitive Information Exposure via assignments vulnerability in LearnDash LMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-1209
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnDash LMSby StellarWP
0
Updated Aug 19, 2026View on NVD →
Detail

LearnDash LMS is a learning management system plugin designed for WordPress, widely used by educators, instructors, and organizations to create and manage online courses. It allows users to upload various assignments and educational materials for learners to access and complete. LearnDash LMS serves as a comprehensive platform for delivering online education and training programs, offering features such as quizzes, assessments, and progress tracking.

The detected vulnerability in LearnDash LMS involves sensitive information exposure via assignments, present in versions prior to 4.10.2. Due to insufficient protection mechanisms, unauthenticated attackers can gain unauthorized access to uploaded assignment files by directly accessing them. This vulnerability poses a risk of exposing confidential educational materials and potentially sensitive information to unauthorized individuals.

The vulnerability manifests when unauthenticated attackers directly access assignment files uploaded via the '/wp-json/wp/v2/sfwd-assignment' endpoint of the WordPress site hosting the LearnDash LMS plugin. Attackers can identify and access assignment files by inspecting JSON responses containing assignment details, including file URLs. By manipulating the URL parameters, attackers can retrieve assignment files, potentially exposing sensitive information stored within them.

Exploiting the sensitive information exposure vulnerability in LearnDash LMS may lead to unauthorized disclosure of confidential educational materials, sensitive course content, and personal information of learners. Attackers can obtain access to assignment files containing sensitive data, such as student submissions, assessments, and instructor feedback, compromising the privacy and integrity of online learning environments.

Protect your online learning environment from the risks posed by the sensitive information exposure vulnerability in LearnDash LMS by leveraging the comprehensive security scanning capabilities of the S4E platform. Join our platform to detect and remediate critical vulnerabilities like CVE-2024-1209, ensuring the confidentiality and integrity of your educational materials and safeguarding the privacy of learners enrolled in your online courses.

 

References

Solution Advice
  • Upgrade LearnDash LMS plugin to version 4.10.2 or later to patch the sensitive information exposure vulnerability.
  • Implement access controls and authentication mechanisms to restrict unauthorized access to assignment files and other sensitive educational materials.
  • Regularly audit file permissions and directory configurations to ensure proper protection of uploaded files and prevent unauthorized access.
  • Educate administrators and instructors on secure file handling practices and the importance of protecting sensitive information in online learning environments.
  • Monitor access logs and implement intrusion detection systems (IDS) to detect and mitigate unauthorized attempts to access assignment files and other sensitive resources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-1209 scanner - Sensitive Information Exposure via assignments vulnerability in LearnDash LMS S4E