CVE-2018-25019
HIGH 7.5EPSS 1.6%
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 1.58% chance of exploitation in the next 30 days, 74th percentile
- Nuclei
- critical
- Published
- 2021-11-01
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- https://lists.openwall.net/full-disclosure/2018/01/10/17
- https://wpscan.com/vulnerability/9444f67b-8e3d-4cf0-b319-ed25e7db383a