plugin

Lifterlms Vulnerabilities

35 known security issues reported for the Lifterlms WordPress plugin. Most recent disclosed Jul 30, 2026.

2 critical 5 high 10 medium 1 low

Running Lifterlms on your site? Check whether your installed version is affected.

Scan your site free

LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 10.0.9 - Authenticated (Custom role+) Stored Cross-Site Scripting

medium

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 10.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom role-level access and abo...

CVSS:
6.4
Affected:
up to 10.0.9
Fixed in:
10.0.10
Disclosed:
Jul 30, 2026

CVE-2026-14207 on NVD →

LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes < 10.0.10 - Authenticated (Subscriber+) Information Exposure

medium

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 10.0.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 10.0.10
Fixed in:
10.0.10
Disclosed:
Jul 30, 2026

CVE-2026-14231 on NVD →

LifterLMS <= 9.2.1 - Authenticated (Custom+) SQL Injection via 'order' Parameter

medium

The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 9.2.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, w...

CVSS:
6.5
Affected:
up to 9.2.1
Fixed in:
9.2.2
Disclosed:
Apr 10, 2026

CVE-2026-5207 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] <= 3.5.3 (unfixed)

unknown

[en] The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a user's identity prior to allowing them to modify their own role via the REST API. The permission check in the update_item_permissions_check...

Affected:
up to 3.5.3
Fix:
No patched version reported
Disclosed:
Nov 13, 2025

CVE-2025-11923 on NVD →

LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege Escalation

high

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a user's identity prior to allowing them to modify their own role via the REST API. The permission check in the update_item_permissions_check() fu...

CVSS:
8.8
Affected:
3.5.3 – 3.41.1, 4.0.0 – 4.21.3, 5.0.0 – 5.10.0, 6.0.0 – 6.11.0, 7.0.0 – 7.8.7, 8.0.0 – 8.0.7, 9.0.0 – 9.0.7, 9.1.0 – 9.1.0
Fixed in:
3.41.2
Disclosed:
Nov 12, 2025

CVE-2025-11923 on NVD →

LifterLMS <= 8.0.6 - Unauthenticated SQL Injection

high

The LifterLMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...

CVSS:
7.5
Affected:
up to 8.0.6
Fixed in:
8.0.7
Disclosed:
Jul 1, 2025

CVE-2025-52717 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 8.0.7

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett LifterLMS allows SQL Injection. This issue affects LifterLMS: from n/a through 8.0.6.

Affected:
up to 8.0.7
Fixed in:
8.0.7
Disclosed:
Jun 27, 2025

CVE-2025-52717 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 8.0.1

unknown

[en] The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 8.0.1
Fixed in:
8.0.1
Disclosed:
May 15, 2025

CVE-2024-13619 on NVD →

LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing

medium

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Post Trashing due to a missing capability check on the delete_access_plan function and the related AJAX calls in all versions up to, and including, 8.0.1. This makes it possible for unauthenticated atta...

CVSS:
5.3
Affected:
up to 8.0.1
Fixed in:
8.0.2
Disclosed:
Mar 18, 2025

CVE-2025-2290 on NVD →

LifterLMS <= 8.0.0 - Reflected Cross-Site Scripting

medium

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 8.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
6.1
Affected:
up to 8.0.0
Fixed in:
8.0.1
Disclosed:
Mar 3, 2025

CVE-2024-13619 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 7.8.6

unknown

[en] The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level acc...

Affected:
up to 7.8.6
Fixed in:
7.8.6
Disclosed:
Dec 18, 2024

CVE-2024-12596 on NVD →

LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion

medium

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subscriber-level access a...

CVSS:
4.3
Affected:
up to 7.8.5
Fixed in:
7.8.6
Disclosed:
Dec 17, 2024

CVE-2024-12596 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 7.7.6

unknown

[en] The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Affected:
up to 7.7.6
Fixed in:
7.7.6
Disclosed:
Sep 6, 2024

CVE-2024-7349 on NVD →

LifterLMS <= 7.7.5 - Authenticated (Admin+) SQL Injection

high

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
7.2
Affected:
up to 7.7.5
Fixed in:
7.7.6
Disclosed:
Sep 5, 2024

CVE-2024-7349 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 7.6.3

unknown

[en] The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute of the lifterlms_favorites shortcode in all versions up to, and including, 7.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exi...

Affected:
up to 7.6.3
Fixed in:
7.6.3
Disclosed:
Jun 5, 2024

CVE-2024-4743 on NVD →

LifterLMS – WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injection via Shortcode

high

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute of the lifterlms_favorites shortcode in all versions up to, and including, 7.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...

CVSS:
8.8
Affected:
up to 7.6.2
Fixed in:
7.6.3
Disclosed:
Jun 4, 2024

CVE-2024-4743 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 7.5.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in LifterLMS.This issue affects LifterLMS: from n/a through 7.5.0.

Affected:
up to 7.5.1
Fixed in:
7.5.1
Disclosed:
Apr 12, 2024

CVE-2024-31363 on NVD →

LifterLMS <= 7.5.0 - Cross-Site Request Forgery

medium

The LifterLMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.0. This is due to missing or incorrect nonce validation on the llms-clone-post action. This makes it possible for unauthenticated attackers to clone posts via a forged request granted they can trick a si...

CVSS:
4.3
Affected:
up to 7.5.0
Fixed in:
7.5.1
Disclosed:
Apr 8, 2024

CVE-2024-31363 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 7.5.2

unknown

[en] The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and including, 7.5.1. This makes it possible for unauthenticated attackers to publish an unrestricted...

Affected:
up to 7.5.2
Fixed in:
7.5.2
Disclosed:
Mar 13, 2024

CVE-2024-0377 on NVD →

LifterLMS – WordPress LMS Plugin for eLearning <= 7.5.1 - Missing Authorization via process_review

medium

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and including, 7.5.1. This makes it possible for unauthenticated attackers to publish an unrestricted numbe...

CVSS:
5.3
Affected:
up to 7.5.1
Fixed in:
7.5.2
Disclosed:
Feb 27, 2024

CVE-2024-0377 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 7.5.0

unknown

[en] The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authenticated attackers, with administrator or LMS manager access and above, to read the contents of a...

Affected:
up to 7.5.0
Fixed in:
7.5.0
Disclosed:
Nov 22, 2023

CVE-2023-6160 on NVD →

LifterLMS <= 7.4.2 - Authenticated(Administrator+) Directory Traversal to Arbitrary CSV File Deletion

low

The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 7.4.2 via the maybe_serve_export function. This makes it possible for authenticated attackers, with administrator or LMS manager access and above, to read the contents of arbitr...

CVSS:
3.3
Affected:
up to 7.4.2
Fixed in:
7.5.0
Disclosed:
Nov 5, 2023

CVE-2023-6160 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 4.21.2

unknown

[en] The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades

Affected:
up to 4.21.2
Fixed in:
4.21.2
Disclosed:
Aug 23, 2021

CVE-2021-24562 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 4.21.1

unknown

[en] The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low...

Affected:
up to 4.21.1
Fixed in:
4.21.1
Disclosed:
May 24, 2021

CVE-2021-24308 on NVD →

LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress < 4.21.2 - Insecure Direct Object Reference

high

The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades

CVSS:
7.5
Affected:
up to 4.21.2
Fixed in:
4.21.2
Disclosed:
May 17, 2021

CVE-2021-24562 on NVD →

LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin <= 4.21.0 - Stored Cross-Site Scripting

medium

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privi...

CVSS:
5.4
Affected:
up to 4.21.1
Fixed in:
4.21.1
Disclosed:
May 10, 2021

CVE-2021-24308 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 4.21.1

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by Ashish Jha (Bluefire Redteam) in WordPress LifterLMS plugin (versions <= 4.21.0).

Affected:
up to 4.21.1
Fixed in:
4.21.1
Disclosed:
May 10, 2021

LMS by LifterLMS <= 4.21.0 - Reflected Cross-Site Scripting

medium

The LMS by LifterLMS plugin for WordPress has a reflected cross-site scripting vulnerability in the in versions up to, and including, 4.21.0 due to insufficient input sanitization and output escaping on the 'coupon_code' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 4.21.1
Fixed in:
4.21.1
Disclosed:
Apr 29, 2021

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 4.21.1

unknown

The LMS by LifterLMS plugin for WordPress has a reflected cross-site scripting vulnerability in the in versions up to, and including, 4.21.0 due to insufficient input sanitization and output escaping on the 'coupon_code' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 4.21.1
Fixed in:
4.21.1
Disclosed:
Apr 29, 2021

LifterLMS Wordpress Plugin <= 3.37.14 - Arbitrary File Write

critical

LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution.

CVSS:
9.8
Affected:
up to 3.37.15
Fixed in:
3.37.15
Disclosed:
Mar 31, 2020

CVE-2020-6008 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 3.37.15

unknown

[en] LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

Affected:
up to 3.37.15
Fixed in:
3.37.15
Disclosed:
Mar 31, 2020

CVE-2020-6008 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 3.35.1

unknown

[en] An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XS...

Affected:
up to 3.35.1
Fixed in:
3.35.1
Disclosed:
Sep 10, 2019

CVE-2019-15896 on NVD →

LMS by LifterLMS <= 3.35.0 - Stored Cross-Site Scripting via Import

critical

An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

CVSS:
9.8
Affected:
up to 3.35.0
Fixed in:
3.35.0
Disclosed:
Sep 9, 2019

CVE-2019-15896 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 8.0.2

unknown
Affected:
up to 8.0.2
Fixed in:
8.0.2

CVE-2025-2290 on NVD →

LifterLMS &#8211; WP LMS for eLearning, Online Courses, &amp; Quizzes [lifterlms] < 4.21.1

unknown

The plugin did not properly sanitise the coupon code during checkout before outputting in back the error message in the page, leading to a reflected Cross-Site Scripting issue

Affected:
up to 4.21.1
Fixed in:
4.21.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database