Junglewise Threat Intelligence

CVE-2026-12843: LearnDash LMS authorization bypass in enrollment

CVE-2026-12843 · Severity: medium · CVSS 5.4 · Published 2026-09-05

Executive brief

LearnDash is a popular WordPress plugin that enables online course delivery and student management. The plugin contains an authorization bypass flaw that allows unauthenticated attackers to enroll users in paid courses without payment, effectively stealing premium educational content and circumventing the revenue model that course creators depend on.

Technical details

The vulnerability is an authorization bypass in LearnDash's enrollment functionality, stemming from insufficient verification of user authorization before processing course enrollment requests. The flaw allows unauthenticated attackers to exploit REST API endpoints (likely via the plugin's public-facing enrollment mechanisms) to arbitrarily enroll users in paid courses without completing payment verification. This vulnerability is network-accessible and requires no authentication or user interaction. Attackers can achieve unauthorized access to premium course content and bypass the payment system entirely. The issue was addressed in security patches released in version 5.1.6.1, which tightened security around REST API endpoints.

Affected products

  • LearnDash LearnDash LMS 4.25.0 - 5.1.6

Timeline

  • 2026-09-05: disclosed
  • 2026-06-29: patched: Version 5.1.6.1 released with REST API security fixes

References

Related threats