{
 "id": "WPSEC-2026-0476",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0476/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0476/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0476/index.md",
 "title": "LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress <= 10.2.1 - Authenticated (Instructor's Assistant+) PHP Object Injection via Lesson Clone and Course Import",
 "description": "The LifterLMS plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via the custom meta values of cloned and imported courses and lessons, which were deserialized with maybe_unserialize() without restricting allowed classes. This makes it possible for authenticated attackers who can edit a lesson, such as instructors and instructor's assistants, to store a serialized object in a custom field and have it instantiated when the lesson is cloned, and for users with permission to import courses to do the same through an import file. No known POP chain is present in the plugin itself; if a POP chain is present via another plugin or theme, it could allow file deletion, data retrieval, or code execution.",
 "plugin": {
  "slug": "lifterlms",
  "name": "LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress",
  "full_name": "LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes",
  "wordpress_org": "https://wordpress.org/plugins/lifterlms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/lifterlms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/lifterlms"
 },
 "type": "OBJECT INJECTION",
 "cwe": [
  "CWE-502"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "10.3.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 10.3.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "10.3.0",
 "remediation": "Update to 10.3.0 or later.",
 "fix_released": "2026-10-05T15:59:46+00:00",
 "published": "2026-10-06T19:43:53+00:00",
 "updated": "2026-10-06T19:05:44.181424+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0476/",
  "https://plugins.svn.wordpress.org/lifterlms/tags/10.3.0/",
  "https://wordpress.org/plugins/lifterlms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/lifterlms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}