{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/learndash/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:learndash:learndash_lms:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:learndash:learndash:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":5.3,"id":"CVE-2024-1208"},{"cvss":5.3,"id":"CVE-2024-1210"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LearnDash LMS (\u003c 4.10.3)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","web-application","wordpress"],"_cs_type":"threat","_cs_vendors":["LearnDash"],"content_html":"\u003cp\u003eLearnDash LMS, a widely used WordPress learning management system, contains critical vulnerabilities (CVE-2024-1208 and CVE-2024-1210) within its REST API implementation. These vulnerabilities permit unauthenticated remote attackers to access sensitive quiz content and examination questions via the \u003ccode\u003e/ldlms/v1/\u003c/code\u003e and \u003ccode\u003e/ldlms/v2/\u003c/code\u003e REST API endpoints. Because the plugin fails to enforce proper authorization checks on these API routes, any visitor can retrieve private assessment data without being enrolled in the associated courses or possessing administrative privileges. This vulnerability exposes proprietary course content and compromises the integrity of assessments that rely on these questions to verify student knowledge. The vulnerability was disclosed and fixed in version 4.10.3 of the LearnDash plugin. Organizations utilizing LearnDash are at risk of data exfiltration and intellectual property theft if they have not patched to the current secure version.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized disclosure of proprietary educational content, including complete sets of quiz and exam questions. This facilitates cheating and undermines the educational integrity of the platform. There are no reports of widespread active exploitation, but the public availability of proof-of-concept exploits significantly increases the likelihood of opportunistic discovery by malicious actors targeting WordPress-based environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the LearnDash LMS plugin to version 4.10.3 or later immediately to resolve CVE-2024-1208 and CVE-2024-1210.\u003c/li\u003e\n\u003cli\u003eAudit WordPress access logs for anomalous requests to the \u003ccode\u003e/wp-json/ldlms/v1/\u003c/code\u003e or \u003ccode\u003e/wp-json/ldlms/v2/\u003c/code\u003e endpoints, specifically monitoring for high-frequency requests from non-authenticated source IPs.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of exposing the LearnDash REST API and, if not required for business functionality, utilize the \u003ccode\u003elearndash_rest_api_enabled\u003c/code\u003e filter in \u003ccode\u003eclass-ld-rest-api.php\u003c/code\u003e to disable the API for sensitive post types.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T08:51:15Z","date_published":"2026-09-03T08:51:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-learndash-api-exposure/","summary":"LearnDash LMS versions prior to 4.10.3 are vulnerable to unauthenticated REST API access (CVE-2024-1208, CVE-2024-1210), allowing unauthorized remote actors to exfiltrate quiz and examination content.","title":"Unauthenticated Information Disclosure in LearnDash LMS","url":"https://feed.craftedsignal.io/briefs/2026-09-learndash-api-exposure/"}],"language":"en","title":"CraftedSignal Threat Feed - LearnDash","version":"https://jsonfeed.org/version/1.1"}