CVE-2026-3079 | StellarWP LearnDash LMS Plugin up to 5.0.3 on WordPress AJAX Action filters[orderby_order] sql injection (EUVD-2026-14691)
A vulnerability described as critical has been identified in StellarWP LearnDash LMS Plugin up to 5.0.3 on WordPress. The affected element is an unknown function of the component AJAX Action Handler. The manipulation of the argument filters[orderby_order] results in sql injection.
This vulnerability is cataloged as CVE-2026-3079. The attack may be launched remotely. There is no exploit available.