Unrestricted File Type Upload Vulnerability in LearnDash LMS Plugin
The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. Authenticated attackers with subscriber-level access and above can upload arbitrary files, including PHP files, to the server. Immediate action is required to prevent potential Remote Code Execution.