{
 "id": "WPSEC-2026-0706",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0706/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0706/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0706/index.md",
 "title": "LifterLMS <= 10.3.1 - Authenticated (Contributor+) Local File Inclusion via lifterlms_checkout Shortcode",
 "description": "The LifterLMS plugin for WordPress is vulnerable to Local File Inclusion via the 'lifterlms_checkout' shortcode in all versions up to, and including, 10.3.1. This is due to the shortcode passing all user-supplied attributes to the template loader, which extracted them into local variables before resolving the template path, combined with template names being used without path traversal or directory containment checks. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite variables such as the template name and include and execute arbitrary PHP files on the server. This can be used to bypass access controls, obtain sensitive data, or achieve code execution where PHP files can be uploaded or otherwise placed on the server.",
 "plugin": {
  "slug": "lifterlms",
  "name": "LifterLMS",
  "full_name": "LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes",
  "wordpress_org": "https://wordpress.org/plugins/lifterlms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/lifterlms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/lifterlms"
 },
 "type": "LFI",
 "cwe": [
  "CWE-98"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 8.8,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "10.3.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 10.3.2"
  ]
 },
 "introduced_in": null,
 "fixed_in": "10.3.2",
 "remediation": "Update to 10.3.2 or later.",
 "fix_released": "2026-10-09T14:44:57+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:24.709735+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0706/",
  "https://plugins.svn.wordpress.org/lifterlms/tags/10.3.2/",
  "https://wordpress.org/plugins/lifterlms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/lifterlms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}