Course Redirects for LearnDash WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Course Redirects for LearnDash plugin for WordPress, affecting all versions up to and including 0.4. The vulnerability arises from inadequate nonce validation in form submissions on the settings page, allowing unauthenticated attackers to alter plugin settings by sending a forged request that tricks a site administrator into clicking a link.
Impact
Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing attackers to manipulate course redirect behaviors or associated data.
Added: Oct 11, 2025, 10:35 AM
Updated: Oct 11, 2025, 10:35 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
7.0remediation
0.0relevance
0.7threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
