{
 "id": "WPSEC-2026-0478",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0478/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0478/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0478/index.md",
 "title": "LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress <= 10.2.1 - Authenticated (Instructor's Assistant+) PHP Object Injection via Course Builder Custom Fields",
 "description": "The LifterLMS plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 10.2.1 via the custom field values submitted when lessons are created or cloned through the course builder, which were passed to maybe_unserialize(). This makes it possible for authenticated attackers with access to the course builder for a course, such as instructors and instructor's assistants, to inject a PHP object. No known POP chain is present in the plugin itself; if a POP chain is present via another plugin or theme on the target site, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.",
 "plugin": {
  "slug": "lifterlms",
  "name": "LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress",
  "full_name": "LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes",
  "wordpress_org": "https://wordpress.org/plugins/lifterlms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/lifterlms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/lifterlms"
 },
 "type": "OBJECT INJECTION",
 "cwe": [
  "CWE-502"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "10.3.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 10.3.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "10.3.0",
 "remediation": "Update to 10.3.0 or later.",
 "fix_released": "2026-10-05T15:59:46+00:00",
 "published": "2026-10-06T19:43:53+00:00",
 "updated": "2026-10-06T19:05:44.181424+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0478/",
  "https://plugins.svn.wordpress.org/lifterlms/tags/10.3.0/",
  "https://wordpress.org/plugins/lifterlms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/lifterlms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}