CVE-2023-28777: Learndash

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3.

Affected products

  • Learndash Learndash: up to and including 4.5.3

Published 2023-10-31. Last modified 2026-06-17.