Description
WordPress Plugin LearnDash LMS is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to reset arbitrary user passwords. WordPress Plugin LearnDash LMS version 4.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.6.0.1 or latest