# LifterLMS <= 10.3.1 - Authenticated (Contributor+) Local File Inclusion via lifterlms_checkout Shortcode

- **ID:** WPSEC-2026-0706
- **Plugin:** LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes (`lifterlms`), https://wordpress.org/plugins/lifterlms/
- **Affected versions:** all versions before 10.3.2
- **Fixed in:** 10.3.2 (Update to 10.3.2 or later.)
- **Severity:** High 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-98
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/lifterlms
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0706/

## Description

The LifterLMS plugin for WordPress is vulnerable to Local File Inclusion via the 'lifterlms_checkout' shortcode in all versions up to, and including, 10.3.1. This is due to the shortcode passing all user-supplied attributes to the template loader, which extracted them into local variables before resolving the template path, combined with template names being used without path traversal or directory containment checks. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite variables such as the template name and include and execute arbitrary PHP files on the server. This can be used to bypass access controls, obtain sensitive data, or achieve code execution where PHP files can be uploaded or otherwise placed on the server.

## References

- https://wpsec.com/vuln/WPSEC-2026-0706/
- https://plugins.svn.wordpress.org/lifterlms/tags/10.3.2/
- https://wordpress.org/plugins/lifterlms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0706/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
