← Vulnerability feed

Vulnerability record · CVE-2020-6009 · published 1 April 2020

CVE-2020-6009: Learndash sql injection vulnerability

Learndash · Learndash

LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

9.8 CVSS 3.1 Critical EPSS 1.8% · top 21.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6009 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-28777Learndash sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.Th…EPSS 0.68%8.8CVE-2023-3105Learndash insecure direct object reference vulnerabilityThe LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the…EPSS 2.2%7.5CVE-2024-56940Learndash uncontrolled resource consumption vulnerabilityAn issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.EPSS 0.59%7.5CVE-2018-25019Learndash unrestricted file upload vulnerabilityThe LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment…EPSS 1.6%5.4CVE-2024-56938Learndash cross-site scripting vulnerabilityLearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class.EPSS 0.33%5.4CVE-2024-56939Learndash cross-site scripting vulnerabilityLearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.EPSS 0.33%5.4CVE-2020-7108Learndash cross-site scripting vulnerabilityThe LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.EPSS 3.5%5.3CVE-2024-1209Learndash information exposure vulnerabilityThe LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file a…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2020-6009), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.