# LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress <= 10.2.1 - Unauthenticated Sensitive Information Exposure via RSS Feeds

- **ID:** WPSEC-2026-0477
- **Plugin:** LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (`lifterlms`), https://wordpress.org/plugins/lifterlms/
- **Affected versions:** all versions before 10.3.0
- **Fixed in:** 10.3.0 (Update to 10.3.0 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/lifterlms
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0477/

## Description

The LifterLMS plugin for WordPress is vulnerable to Sensitive Information Exposure via RSS feeds in all versions up to, and including, 10.2.1. Lessons, quizzes and certificates were included in list and search feeds, and the content restriction checks did not run in those non-singular contexts. This makes it possible for unauthenticated attackers to read restricted lesson, quiz and certificate content that should only be available to enrolled students or members.

## References

- https://wpsec.com/vuln/WPSEC-2026-0477/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.0/
- https://wordpress.org/plugins/lifterlms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0477/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
