Vulnerabilities / LifterLMS / WPSEC-2026-0706

LifterLMS <= 10.3.1 - Authenticated (Contributor+) Local File Inclusion via lifterlms_checkout Shortcode

High 8.8 CWE-98Fixed in 10.3.2
ID
WPSEC-2026-0706
Plugin
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (lifterlms)
Affected
all versions before 10.3.2
Remediation
Update to 10.3.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-98
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
LifterLMS on WPSec AttackSurface
Fix released
Published

Description

The LifterLMS plugin for WordPress is vulnerable to Local File Inclusion via the 'lifterlms_checkout' shortcode in all versions up to, and including, 10.3.1. This is due to the shortcode passing all user-supplied attributes to the template loader, which extracted them into local variables before resolving the template path, combined with template names being used without path traversal or directory containment checks. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite variables such as the template name and include and execute arbitrary PHP files on the server. This can be used to bypass access controls, obtain sensitive data, or achieve code execution where PHP files can be uploaded or otherwise placed on the server.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0